generated: '2026-08-23' method: searched source: https://trust.uniphore.com/ summary: >- A responsible-disclosure channel IS published — by Uniphore, on the SafeBase-hosted trust center that covers the InfoWorks product since the 2024 acquisition. It is a mailbox and a subject-line convention, not an RFC 9116 security.txt and not a bug bounty. program: published: true type: responsible-disclosure operator: Uniphore contact: uniphore_trust@uniphore.com instructions: >- The trust center's "Report issue" control opens an email to uniphore_trust@uniphore.com with the subject line "SafeBase Responsible Disclosure Report for Uniphore". url: https://trust.uniphore.com/ status: 200 checked: '2026-08-23' attribution_note: >- Uniphore acquired Infoworks in 2024 and operates it as the InfoWorks product — the corporate site serves the product page at uniphore.com/infoworks/, www.infoworks.io 301s there, and release note 6.1.3.2 (IPD-28347) records the Infoworks logo being replaced by the Uniphore logo in the product UI. The disclosure channel is therefore the correct route for an InfoWorks vulnerability, even though the trust center does not name InfoWorks by name. bug_bounty: found: false probed: [hackerone, bugcrowd, intigriti] note: No public bounty program located for Uniphore or Infoworks. security_txt: found: false probes: - url: https://www.uniphore.com/.well-known/security.txt status: 404 - url: https://www.uniphore.com/security.txt status: 404 - url: https://docs.infoworks.io/.well-known/security.txt status: 200 note: SPA shell (text/html), not a security.txt. Recorded as a miss. remedy: >- Publishing an RFC 9116 /.well-known/security.txt at www.uniphore.com pointing Contact at uniphore_trust@uniphore.com and Policy at https://trust.uniphore.com/ would make an already-real program machine-discoverable. Today a scanner finds nothing. gaps: - No published disclosure policy document (scope, safe harbour, response SLA) — only a mailbox. - No PGP key advertised. - No CVE/advisory feed for the Infoworks product.