generated: '2026-09-19' method: searched source: https://www.fodda.ai/compliance-dossier + https://raw.githubusercontent.com/piers-fawkes/fodda-mcp/main/SECURITY_SUMMARY.md checked: '2026-09-19' summary: 'Fodda publishes a named, first-party vulnerability-reporting channel — security@fodda.ai — on its Compliance Dossier page ("Security & vulnerability reporting: security@fodda.ai"; "direct vulnerability triage at security@fodda.ai") and in the fodda-mcp repository''s SECURITY_SUMMARY.md. It ships no /.well-known/security.txt on any host, no dedicated disclosure policy page, no safe-harbor statement and no bug bounty. probe-security-programs.py wrote nothing because its bar is a security.txt Policy line, a bounty listing or a disclosure page; this file records the email channel that does exist.' program: published: true kind: email-only contact: mailto:security@fodda.ai quotes: - 'Security & vulnerability reporting: security@fodda.ai | Procurement & compliance: compliance@fodda.ai' - founder-led engineering access, verified human oversight telemetry via Slack, and direct vulnerability triage at security@fodda.ai location: https://www.fodda.ai/compliance-dossier document_last_updated: 2026-08-27 (per llms.txt) policy: page: null safe_harbor_documented: false scope_documented: false response_sla_documented: false disclosure_timeline_documented: false rewards: none-published bug_bounty: platform: null hackerone: false bugcrowd: false intigriti: false security_txt: served: false probes: - url: https://www.fodda.ai/.well-known/security.txt status: 404 - url: https://api.fodda.ai/.well-known/security.txt status: 404 - url: https://mcp.fodda.ai/.well-known/security.txt status: 404 - url: https://clerk.fodda.ai/.well-known/security.txt status: 404 - url: https://app.fodda.ai/.well-known/security.txt status: 200 SPA shell (not a document) note: A security.txt naming the existing security@fodda.ai address would be a one-file fix. related_pages: - url: https://www.fodda.ai/security status: 200 note: 'Security overview (marketing-level: private graph infrastructure, data isolation, deterministic retrieval, no training on client data).' - url: https://www.fodda.ai/blog/security-refresh-2026 status: 200 note: '2026-02-12: NIST CSF 2.0 alignment, SOC 2 Type II readiness roadmap by Q4 2026, GCP hosting, read-only data model, tenant isolation.'