generated: '2026-08-04' method: searched probe: true source: https://opengov.com/security/ policy: - https://opengov.com/security/ contact: - security@opengov.com - trust@opengov.com - grc@opengov.com program: type: responsible disclosure (coordinated vulnerability disclosure) bug_bounty: false platform: none — reported directly to security@opengov.com, not via HackerOne/Bugcrowd/Intigriti statement: OpenGov values the security research community and welcomes collaboration to make our products and services more secure. safe_harbor: true safe_harbor_text: OpenGov will not initiate, pursue or recommend any law enforcement or civil lawsuits related to the specific actions taken by you to discover a security vulnerability. response_targets: acknowledgement: 3 business days initial_triage: 10 business days in_scope: - OpenGov web applications - OpenGov APIs - OpenGov mobile applications - authentication flows out_of_scope: - third-party services - corporate infrastructure - denial-of-service testing security_txt: published: false probed: - url: https://opengov.com/.well-known/security.txt status: 404 - url: https://developer.opengov.com/.well-known/security.txt status: 200 rejected: SPA HTML shell, not an RFC 9116 document gap: >- The disclosure policy exists and is good, but it is not machine-discoverable. Publishing https://opengov.com/.well-known/security.txt with Contact: mailto:security@opengov.com and Policy: https://opengov.com/security/ would make it readable by every automated scanner and agent. evidence: - source: https://opengov.com/security/ kind: disclosure-policy-page http_status: 200 fetched: '2026-08-04' - source: https://trust.opengov.com/ kind: trust-center http_status: 200 fetched: '2026-08-04'