generated: '2026-09-19' method: searched source: https://humanmirror.fr/downloads/humanmirror-audit-0.2.0.tgz (package/SECURITY.md) program: type: e-mail disclosure policy contact: security@humanmirror.fr policy_url: null bug_bounty: false platform: null safe_harbor: null acknowledgement: HumanMirror will acknowledge actionable reports and coordinate remediation before public disclosure. statement: Please report vulnerabilities privately to security@humanmirror.fr with the affected version, reproduction steps and impact. Do not include live credentials or third-party personal data. evidence: - url: https://humanmirror.fr/downloads/humanmirror-audit-0.2.0.tgz http_status: 200 fetched: '2026-09-19' file: package/SECURITY.md sha256_tarball: null - url: https://humanmirror.fr/.well-known/security.txt http_status: 404 - url: https://humanmirror.fr/security.txt http_status: 404 - url: https://humanmirror.fr/security/ http_status: 404 note: The only published disclosure policy is the SECURITY.md shipped inside the first-party CLI tarball (also referenced from its README as 'Responsible disclosure'). No RFC 9116 security.txt, no /security page, no HackerOne/Bugcrowd/Intigriti program was found. The Security pointer is emitted on the strength of this provider-authored policy document; SecurityTxt is not.