generated: '2026-08-14' method: searched probe: true source: https://github.com/FullEnrich/fullenrich-skills/blob/HEAD/SECURITY.md description: >- FullEnrich publishes a written vulnerability disclosure policy — but only inside a source repository (SECURITY.md in its Agent Skills repo), not on its website and not at /.well-known/security.txt. The policy names a private reporting address, sets embargo expectations, and defines authorized-testing boundaries. policy: - https://github.com/FullEnrich/fullenrich-skills/blob/HEAD/SECURITY.md contact: - support@fullenrich.com terms: reporting_channel: Private email to support@fullenrich.com required_in_report: - Reproduction steps - Potential impact - Relevant logs with credentials and personal data removed embargo: >- Reporters must not disclose an unpatched vulnerability publicly, and must wait until FullEnrich confirms a patch or mitigation is available. authorized_testing_boundaries: - Use only accounts, workspaces and data you own or are explicitly authorized to test - Do not access another customer's data - Do not disrupt production or degrade service availability - No denial-of-service testing safe_harbor_stated: false bug_bounty: false bounty_platform: null reward: none stated related: trust_center: https://fullenrich.com/trust security_page: https://fullenrich.com/security detail: security/fullenrich-trust-center.yml security_txt: served_by_fullenrich: false probed: - url: https://fullenrich.com/.well-known/security.txt http_status: 404 - url: https://app.fullenrich.com/.well-known/security.txt http_status: 200 note: HTML app shell (SPA catch-all), not an RFC 9116 document - url: https://docs.fullenrich.com/.well-known/security.txt http_status: 404 - url: https://mcp.fullenrich.com/.well-known/security.txt http_status: 200 note: HTML shell (catch-all), not an RFC 9116 document - url: https://help.fullenrich.com/.well-known/security.txt http_status: 200 note: >- A real RFC 9116 document — but it is INTERCOM'S, serving the help-center platform, and it routes reports to Intercom rather than FullEnrich. Not counted as a FullEnrich security.txt. gaps: - >- The policy is discoverable only by browsing a GitHub repository. Nothing on fullenrich.com, docs.fullenrich.com or the help center links to it. - >- No /.well-known/security.txt on any FullEnrich-controlled host, so automated disclosure tooling cannot find a contact. - >- Reports go to the general support inbox rather than a dedicated security@ alias. - No safe-harbor / non-prosecution statement. evidence: - source: https://github.com/FullEnrich/fullenrich-skills/blob/HEAD/SECURITY.md kind: repository security policy http_status: 200 - source: https://fullenrich.com/trust kind: trust center http_status: 200