generated: '2026-09-19' method: searched probe: true source: well-known/getemboss-ai-security.txt (probe-security-programs.py) upgraded from https://getemboss.ai/security policy: - https://getemboss.ai/security#reporting-a-vulnerability contact: - mailto:contact@getemboss.ai response_commitment: 'Email contact@getemboss.ai and we will reply within five business days.' bug_bounty: false program_platform: null safe_harbor: not stated scope: not stated evidence: - source: well-known/getemboss-ai-security.txt kind: security.txt (RFC 9116) fields: {Contact: 'mailto:contact@getemboss.ai', Expires: '2027-09-19T23:35:37.029Z', Preferred-Languages: en, Canonical: 'https://getemboss.ai/.well-known/security.txt'} gap: No Policy, Encryption, Acknowledgments or Hiring field; the Contact is the general contact address, not a security@ mailbox. - source: https://getemboss.ai/security kind: security page keywords: ['Reporting a vulnerability', 'reply within five business days', 'security.txt'] note: A short "Reporting a vulnerability" section naming the same address and pointing at the security.txt; the page otherwise describes document handling (TLS in transit, hashed keys, ephemeral deletion, fax staging deleted within 24 hours) rather than a disclosure programme. probes: - {url: 'https://getemboss.ai/.well-known/security.txt', status: 200} - {url: 'https://getemboss.ai/security', status: 200} - {url: 'https://getemboss.ai/trust', status: 404} - {url: 'https://api.getemboss.ai/.well-known/security.txt', status: 404}