generated: '2026-08-25' method: searched source: https://trust.merlyn.org/ note: >- Merlyn Mind publishes a security reporting address on its trust center but no formal vulnerability disclosure policy, no safe-harbor statement, no /.well-known/security.txt (probed 404 on www.merlyn.org and portal.merlyn.org, 403 on the API Gateway hosts — see well-known/merlyn-mind-well-known.yml) and no bug bounty program on HackerOne, Bugcrowd or Intigriti. What exists is a single monitored contact address. security_contact: security@merlyn.org contact_source: https://trust.merlyn.org/ policy_url: null safe_harbor: false security_txt: false bug_bounty: program: false platform: null disclosure_channel: email evidence: - url: https://trust.merlyn.org/ status: 403 note: >- Cloudflare bot challenge to the raw crawler; security@merlyn.org read from the browser-agent render of the same URL. - url: https://www.merlyn.org/.well-known/security.txt status: 404 - url: https://portal.merlyn.org/.well-known/security.txt status: 404