generated: '2026-08-26' method: searched source: https://security.posh.ai/item/responsible-disclosure-policy program_type: responsible-disclosure-policy bug_bounty: false bug_bounty_platform: null policy_url: https://security.posh.ai/item/responsible-disclosure-policy contact: null security_txt: false note: >- Posh publishes a named Responsible Disclosure Policy as an item inside its SafeBase trust center. The trust center states verbatim: "To report a potential security issue, please follow the guidelines in our Responsible Disclosure Policy." No RFC 9116 /.well-known/security.txt is served on any Posh host (all probed 404/403), and no public bug-bounty program was found on HackerOne, Bugcrowd or Intigriti. The policy item itself returns HTTP 403 to a command-line agent — the SafeBase bot challenge — so the reporting email, scope and safe-harbor terms could not be read in this pass and are recorded as unknown rather than guessed. gaps: - no /.well-known/security.txt on www.posh.ai, api.poshdevelopment.com or app.poshdevelopment.com - policy body not machine-readable (JS-rendered SafeBase portal, 403 to non-browser agents) - no published reporting address outside the gated policy document evidence: - url: https://security.posh.ai/item/responsible-disclosure-policy status: 403 - url: https://security.posh.ai/ status: 403 - url: https://www.posh.ai/.well-known/security.txt status: 404 - url: https://api.poshdevelopment.com/.well-known/security.txt status: 404