generated: '2026-08-26' method: probed source: >- Live probes of /.well-known/security.txt on www.osano.com, api.osano.com, uc.api.osano.com, developers.osano.com, docs.osano.com and bots.osano.com, plus a search of osano.com and developers.osano.com for a disclosure/bug-bounty page. published: false note: >- NO published vulnerability disclosure surface found. There is no security.txt on any Osano host (RFC 9116), no /security or /security/disclosure page (www.osano.com/security returns 404), no HackerOne / Bugcrowd / Intigriti program, and no security@ contact stated on a public page. Osano does publish that it pen-tests and scans nightly (see security/osano-trust-center.yml) and runs a Vanta trust center, but neither tells an outside researcher where to send a finding. This is an honest absence, not a probe failure: every path below returned a real status code. evidence: - url: https://www.osano.com/.well-known/security.txt status: 404 - url: https://api.osano.com/.well-known/security.txt status: 404 - url: https://uc.api.osano.com/.well-known/security.txt status: 404 - url: https://developers.osano.com/.well-known/security.txt status: 404 - url: https://docs.osano.com/.well-known/security.txt status: 404 - url: https://bots.osano.com/.well-known/security.txt status: 404 - url: https://www.osano.com/security status: 404 bug_bounty: null disclosure_policy_url: null security_contact: null