generated: '2026-08-23' method: searched probe: true source: https://www.immutable.com/trust policy_url: https://www.immutable.com/trust security_contact: security@immutable.com security_txt: served: false note: >- No /.well-known/security.txt on any Immutable host (immutable.com, www.immutable.com, api.immutable.com, api.sandbox.immutable.com, docs.immutable.com, hub.immutable.com, auth.immutable.com all 404). The disclosure programme is real but is only discoverable from the Trust page — an RFC 9116 file would make it machine-findable. bug_bounty: programs: - platform: Bugcrowd url: https://bugcrowd.com/engagements/immutable http_status: 200 - platform: Immunefi url: https://immunefi.com/bug-bounty/immutable/information/ http_status: 200 note: >- Immunefi is the web3/smart-contract bounty platform; Immutable runs both, splitting application-layer reports (Bugcrowd) from on-chain protocol reports (Immunefi). statement: >- "Found a vulnerability? We value the contributions of the security community. Please report potential security issues via our bug bounty programs at Bugcrowd or Immunefi, or get in touch with security@immutable.com so we can investigate and resolve them quickly." — https://www.immutable.com/trust evidence: - source: https://www.immutable.com/trust http_status: 200 kind: disclosure page keywords: - vulnerability - security research - bug bounty - security issue - bugcrowd - immunefi - security@ - source: https://www.immutable.com/.well-known/security.txt http_status: 404 kind: negative probe