generated: '2026-08-13' method: searched probe: true product: Nexad / Soku (About Intelligence, Inc.) notes: >- Nexad publishes a real, specific vulnerability-disclosure policy — but NOT where the standard probes look. /.well-known/security.txt returns 404 on nex.ad, soku.ai and docs.nex.ad, and /security and /trust are 404 on soku.ai, so the deterministic probe (probe-security-programs.py) recorded vdp=none. The policy lives in SECURITY.md at the root of the company's public GitHub repository, About-Intelligence/soku-cli, which the GitHub org (login About-Intelligence, display name "Nexad", blog https://nex.ad, email ceo@nex.ad) plainly owns. It names a private reporting channel, a security mailbox, a required report format, an acknowledgement SLA and a supported-versions statement. Recording it here is a search hit, not an inference. The gap worth flagging to the provider is distribution, not substance: a two-line /.well-known/security.txt pointing at this policy would make it machine-discoverable. policy: - https://github.com/About-Intelligence/soku-cli/blob/main/SECURITY.md contact: - security@soku.ai - https://github.com/About-Intelligence/soku-cli/security/advisories/new reporting: private_channel: GitHub private vulnerability reporting email: security@soku.ai public_issues_prohibited: true required_details: - Description of the vulnerability and its impact - Steps to reproduce, with a proof of concept where available - Affected version (`soku --version`) acknowledgement_sla: 3 business days remediation_timeline: Provided after triage. supported_versions: policy: Security fixes are applied to the latest published release on npm (@soku-ai/cli). Older versions are not maintained. credential_handling: >- The policy documents local token storage (OS keychain via keytar when available, otherwise a file-backed store), instructs reporters never to paste tokens into issues, logs or pull requests, and gives an explicit rotation path (`soku auth logout` then `soku auth login`). bug_bounty: present: false platform: null note: No HackerOne / Bugcrowd / Intigriti program found. evidence: - source: https://raw.githubusercontent.com/About-Intelligence/soku-cli/main/SECURITY.md kind: SECURITY.md http_status: 200 fetched: '2026-08-13' file: security/nexad-security-policy.md - source: https://api.github.com/orgs/About-Intelligence kind: ownership-verification http_status: 200 detail: 'GitHub org About-Intelligence: name "Nexad", blog https://nex.ad, email ceo@nex.ad' fetched: '2026-08-13' - source: https://nex.ad/.well-known/security.txt kind: negative-probe http_status: 404 fetched: '2026-08-13' - source: https://soku.ai/.well-known/security.txt kind: negative-probe http_status: 404 fetched: '2026-08-13'