generated: '2026-08-26' method: probed source: live probes of OSARO's public web surface program: none-published note: >- OSARO publishes no vulnerability disclosure policy, no security contact and no bug bounty. /.well-known/security.txt returns 404 (RFC 9116 absent), and /responsible-disclosure, /vulnerability-disclosure and /legal/security all 404. /security is not a disclosure page — it 301s to the SOC 2 newsroom announcement. No HackerOne, Bugcrowd or Intigriti program was found. No `type: Security` pointer is emitted, because there is no disclosure surface for it to point at. The only published security contact route is the general https://www.osaro.com/contact form. For a SOC 2 Type II company this is the single clearest, cheapest gap to close. evidence: - url: https://www.osaro.com/.well-known/security.txt status: 404 - url: https://www.osaro.com/responsible-disclosure status: 404 - url: https://www.osaro.com/legal/security status: 404 - url: https://www.osaro.com/security status: 301 redirects_to: https://www.osaro.com/blog/osaro-completes-soc-2-type-ii-audit-reinforcing-its-commitment-to-customer-trust-and-data-security