generated: '2026-08-22' method: probed source: >- probe-security-programs.py plus direct probes of the Hypori web and documentation hosts, 2026-08-22. published: false security_txt: false bug_bounty: false disclosure_page: false contact: null note: >- Hypori publishes no vulnerability disclosure program that a researcher could find. There is no /.well-known/security.txt on hypori.com, www.hypori.com or docs.hypori.com (404 on each, against hosts that return real 404s — see well-known/hypori-well-known.yml). No HackerOne, Bugcrowd or Intigriti program was found, and /security and /trust are 404 on www.hypori.com. The legal hub carries privacy, terms, EULA, acceptable-use and DPA documents but no security-reporting policy. The only published security-adjacent contact routes are privacy@hypori.com and the general support page. Because there is no disclosure surface, no Security pointer is emitted in apis.yml. probes: - url: https://www.hypori.com/.well-known/security.txt status: 404 - url: https://hypori.com/.well-known/security.txt status: 404 - url: https://docs.hypori.com/.well-known/security.txt status: 404 - url: https://www.hypori.com/security status: 404 - url: https://www.hypori.com/trust status: 404 remedy: >- Publish an RFC 9116 /.well-known/security.txt naming a security contact and a disclosure policy URL. For a FedRAMP High / IL5 vendor this is the cheapest missing artifact on the profile, and its absence is conspicuous next to the certifications that are in place.