generated: '2026-08-13' method: searched probe: true source: https://www.oneshot.ai/handlingdata note: >- OneShot publishes a named security contact but NO vulnerability disclosure program. There is no security.txt on any host, no responsible-disclosure or vulnerability-disclosure page, and no bug bounty on HackerOne, Bugcrowd or Intigriti. `infosec@oneshot.ai` appears once, in the "Guide to Handling of Customer Data" document, as a general information security contact for customers and prospective customers — not as a disclosure channel. Because there is no disclosure policy, NO `Security` pointer is emitted in apis.yml; the security_disclosure check is correctly unearned. Recorded so a later pass does not re-derive the contact as if it were a program. policy: [] contact: - infosec@oneshot.ai bug_bounty: null evidence: - source: https://www.oneshot.ai/handlingdata http_status: 200 kind: security contact in published data-handling guide quote: 'For additional information, please contact infosec@oneshot.ai' probes_missed: - url: https://www.oneshot.ai/.well-known/security.txt status: 404 - url: https://www.oneshot.ai/security status: 404 - url: https://www.oneshot.ai/responsible-disclosure status: 404 note: not present in sitemap.xml - url: https://oneshot.ai/.well-known/security.txt status: 301 - url: https://app.oneshot.ai/.well-known/security.txt status: 200 soft_200: true note: SPA catch-all HTML shell, not a security.txt