generated: '2026-08-29' method: searched source: https://www.lindy.ai/security provider: Lindy providerId: lindy description: >- Vulnerability-disclosure posture for Lindy. Lindy publishes a real security page describing proactive testing and an incident-response playbook, and offers a named security contact — but no machine-readable disclosure surface: no security.txt on any host, no published disclosure policy page, no safe harbour statement, and no bug bounty program on HackerOne, Bugcrowd or Intigriti. security_page: url: https://www.lindy.ai/security status: 200 claims: - Regular vulnerability scans and penetration tests - Real-time monitoring with unusual activity flagged and routed to the team - Incident-response playbook with defined roles, timelines and communication contact: label: Contact Security route: contact form linked from the security page generic_support: support@lindy.ai security_txt: published: false probes: - url: https://www.lindy.ai/.well-known/security.txt status: 404 - url: https://lindy.ai/.well-known/security.txt status: 404 - url: https://docs.lindy.ai/.well-known/security.txt status: 404 - url: https://public.lindy.ai/.well-known/security.txt status: 404 disclosure_policy: published: false url: null safe_harbor: published: false bug_bounty: program: none-found platforms_checked: - HackerOne - Bugcrowd - Intigriti trust_center: url: https://app.drata.com/trust/9cb791f0-0c38-11ee-865f-029d78a187d9 artifact: security/lindy-trust-center.yml note: >- The trust center is the documented route for requesting SOC 2 reports and compliance summaries. It returned 403 to our crawler (an ordinary Drata bot policy, not a dead page) and is linked from both www.lindy.ai/security and the site footer. recommendation: >- Publishing an RFC 9116 /.well-known/security.txt on www.lindy.ai naming the existing security contact would make an already-real program machine-readable at essentially zero cost. maintainers: - FN: Kin Lane email: kin@apievangelist.com