generated: '2026-08-04' method: searched probe: false probe_note: >- 0-working/probe-security-programs.py returned vdp=none — /.well-known/security.txt is a 404 on every H2O.ai host, and both h2o.ai/security and trust.h2o.ai render client-side so the probe's keyword check on raw HTML found nothing. The findings below were read from the rendered pages on 2026-08-04. security_txt: published: false probed: - {url: 'https://h2o.ai/.well-known/security.txt', http_status: 404} - {url: 'https://docs.h2o.ai/.well-known/security.txt', http_status: 404} - {url: 'https://h2ogpte.genai.h2o.ai/.well-known/security.txt', http_status: 200, result: html-catchall, valid: false} policy: - https://h2o.ai/security/ - https://h2o.ai/security/report-vulnerability contact: - security@h2o.ai - sesecurity@h2o.ai bug_bounty: program: null platform: null note: >- No HackerOne, Bugcrowd or Intigriti program was found for H2O.ai. Reporting is via the intake page at h2o.ai/security/report-vulnerability and the Trust Center contacts. advisories: url: https://h2o.ai/security/bulletins description: >- H2O.ai publishes security bulletins. The Trust Center also posts CVE responses — at capture time it carried a statement that H2O.ai had identified no externally exposed systems affected by CVE-2025-55182 (React / Next.js). pgp_key: null safe_harbor: not-published evidence: - {source: 'https://h2o.ai/security/', http_status: 200, fetched: '2026-08-04', quote: 'To report a possible security vulnerability, please submit here (/security/report-vulnerability)'} - {source: 'https://h2o.ai/security/report-vulnerability', http_status: 200, fetched: '2026-08-04'} - {source: 'https://trust.h2o.ai/', http_status: 200, fetched: '2026-08-04', note: 'lists security@h2o.ai for general security support and sesecurity@h2o.ai for responsible disclosure / vulnerability reports'} gaps: - No RFC 9116 /.well-known/security.txt on any host - No published safe-harbor statement or disclosure timeline - No bug bounty program