generated: '2026-09-19' method: searched source: https://registry.npmjs.org/@virixlabs/humanbrowser/-/humanbrowser-5.0.3.tgz (package/SECURITY.md) probed: - {url: 'https://humanbrowser.cloud/.well-known/security.txt', status: 404, fetched: '2026-09-19'} - {url: 'https://humanbrowser.cloud/security.txt', status: 404, fetched: '2026-09-19'} - {url: 'https://agent.humanbrowser.cloud/.well-known/security.txt', status: 404, fetched: '2026-09-19'} - {url: 'https://humanbrowser.cloud/security', status: 404, fetched: '2026-09-19'} - {url: 'https://github.com/VirixLabs/humanbrowser', status: 404, fetched: '2026-09-19', note: 'the repository that would carry SECURITY.md on the web is unreachable'} summary: >- A real, provider-authored vulnerability disclosure policy exists, but it is published only inside the npm package (SECURITY.md in @virixlabs/humanbrowser 5.0.3) — not as RFC 9116 security.txt on either host, not on a /security page, and not on a reachable GitHub repository. probe-security-programs.py therefore found nothing on the web surface (vdp=none). The policy names a contact, an acknowledgement SLA, a remediation target, an in-scope list that covers the cloud service and not just the SDK, and a 90-day coordinated disclosure window. No bug bounty. policy: contact: security@virixlabs.com channel: email acknowledgement_sla: within 48 hours remediation_target: remediation plan within 7 days for high-severity issues coordinated_disclosure_window: 90 days from report, or until a fix ships and customers have had at least 7 days to update — whichever is later bug_bounty: false bug_bounty_note: '"We do not currently run a paid bug-bounty program but will publicly credit researchers (with permission) in our changelog." No changelog is published (/changelog 404).' scope: in_scope: - the SDK package @virixlabs/humanbrowser - the MCP server shim (named as @virixlabs/mcp-human-browser — no such npm package exists; the shim ships inside @virixlabs/humanbrowser) - the A2A endpoint at agent.humanbrowser.cloud/a2a - viewer URL handling (humanbrowser.cloud/a/*) - the token-issuance and billing surface (humanbrowser.cloud/api/*) out_of_scope: - third-party dependencies - social engineering, phishing, non-technical attacks - denial of service ("rate limits are intentional") - the anti-bot evasion techniques themselves ("by design") quote: >- "If you discover a security issue in Human Browser (this SDK, the MCP server, or the cloud service at humanbrowser.cloud), please report it privately so we can fix it before it's disclosed publicly. Email: security@virixlabs.com. We will acknowledge receipt within 48 hours and aim to send a remediation plan within 7 days for high-severity issues." web_surface: security_txt: false security_page: false note: The Privacy Policy (section 10) states TLS everywhere, API tokens hashed at rest, per-customer browser-profile isolation, and breach notification to affected users and the ICO within 72 hours; the Terms (section 3) ask users to report a suspected key compromise by email.