generated: '2026-08-26' method: probed source: live probes of every Navina host note: >- No vulnerability disclosure program was found. This file records an absence, and NO `Security` pointer is emitted in apis.yml, because Navina publishes no security policy, disclosure page or security contact that a researcher could use. Recorded so a later run does not re-probe blind, and so the gap is visible to Navina as something it can fix cheaply (an RFC 9116 security.txt). program: present: false type: null bounty_platform: null security_txt: present: false probes: - url: https://www.navina.ai/.well-known/security.txt status: 404 - url: https://api.navina.ai/.well-known/security.txt status: 403 - url: https://app.navina.ai/.well-known/security.txt status: 403 - url: https://status.navina.ai/.well-known/security.txt status: 404 - url: https://trust.navina.ai/.well-known/security.txt status: 200 note: >- Not a security.txt. Angular SPA catch-all returning the trust-center HTML shell. Treated as a miss. disclosure_pages: - url: https://www.navina.ai/security status: 404 - url: https://www.navina.ai/trust status: 404 security_contact: published: false note: >- The only public contact address Navina publishes is the general mailto:info@navina.ai on its website footer. No security-specific address is published. A trust center exists at https://trust.navina.ai/ and may carry a contact route behind its client-side app, but nothing is asserted here that was not observed.