generated: '2026-07-19' method: searched probe: true policy: - https://www.gohumanfirst.com/security/coordinated-vulnerability-disclosure-policy pgp_key: https://assets.website-files.com/62b4d0b7b1c828cbe3155f12/63bd00e4c7e2f15d1e025d3b_humanfirst-pgp-key.txt bug_bounty: false program: Coordinated Vulnerability Disclosure scope: - web portal (app.gohumanfirst.com) - AWS-hosted web infrastructure - GitHub repositories out_of_scope: - social engineering - physical security - third-party software response_target: 10 days notes: >- Good-faith Coordinated Vulnerability Disclosure program. PGP encryption strongly preferred; security contact email published on the policy page. No bounties paid and no hall of fame; safe-harbor for good-faith research. evidence: - source: https://www.gohumanfirst.com/security/coordinated-vulnerability-disclosure-policy kind: disclosure-policy