generated: '2026-08-04' method: searched probe: true probe_result: >- probe-security-programs.py returned vdp=none — Graphite serves no /.well-known/security.txt (404 on graphite.com and api.graphite.dev, probed 2026-08-04) and has no /security, /trust or /responsible-disclosure page. What follows was found by reading the published documentation instead. policy: - https://graphite.com/docs/privacy-and-security - https://trust.cursor.com contact: - security@graphite.com security_txt: present: false probed: - {url: 'https://graphite.com/.well-known/security.txt', http_status: 404} - {url: 'https://graphite.com/security.txt', http_status: 404} - {url: 'https://api.graphite.dev/.well-known/security.txt', http_status: 404} bug_bounty: present: false platforms: [] note: >- No HackerOne, Bugcrowd, or Intigriti program was found for graphite.com. The trust center is operated by the parent company (trust.cursor.com); any bounty program would live there and could not be confirmed anonymously — the page is a JavaScript application that serves only a title to an unauthenticated fetch. security_practices: soc2_type_ii: true continuous_penetration_testing: true encryption_in_transit: true encryption_at_rest: true token_encryption: aes-256-cbc with a secret held in AWS Secrets Manager layered_key_separation: >- Database contents are additionally encrypted with a key stored in a separate service, so a database compromise alone does not yield GitHub API tokens. ai_data_handling: >- AI features are opt-in and do not store or train on customer data; AI Summarize is PR-by-PR opt-in and runs on Anthropic's API under terms that exclude customer source code from training sets. code_indexing: >- Opt-in, time-limited code indexing service; documented separately at /docs/code-indexing-security. source: https://graphite.com/docs/privacy-and-security evidence: - source: https://graphite.com/docs/privacy-and-security kind: documentation quote: >- "If you have more questions about this feature, don't hesitate to shoot us a message on Slack or email security@graphite.com." - source: https://graphite.com/docs/privacy-and-security kind: documentation quote: >- "We are SOC 2 Type II compliant... We also continuously pen test." gaps: - No RFC 9116 /.well-known/security.txt published on any Graphite host. - No dedicated responsible-disclosure or vulnerability-reporting page. - No stated response-time or safe-harbour commitment for reporters. x-evidence: fetched: '2026-08-04' urls: - {url: 'https://graphite-58cc94ce.mintlify.dev/docs/privacy-and-security.md', http_status: 200} - {url: 'https://trust.cursor.com', http_status: 200, content_type: text/html}