generated: '2026-08-27' method: searched source: >- https://www.pynt.io/trust-center and https://github.com/pynt-io/pynt/blob/main/SECURITY.md provider: Pynt providerId: pynt published: true program: type: vulnerability disclosure policy bug_bounty: false platform: null note: >- No HackerOne, Bugcrowd or Intigriti program was found. Pynt runs a self-hosted VDP documented as a SECURITY.md in its own public GitHub repository and linked from its trust center as "Read our VDP Github Policy". policy: url: https://github.com/pynt-io/pynt/blob/main/SECURITY.md raw_url: https://raw.githubusercontent.com/pynt-io/pynt/main/SECURITY.md http_status: 200 fetched: '2026-08-27' title: Security and Disclosure Information Policy for Pynt's contact: email: support@pynt.io source: SECURITY.md "Reporting a Vulnerability" and trust-center "Report a vulnerability" note: >- The disclosure contact is the general support mailbox, not a dedicated security@ address, and no PGP key is published. terms: acknowledgement_sla: 3 working days acknowledgement_sla_source: SECURITY.md "We aim to acknowledge receipt of your report within 3 working days." coordinated_disclosure_required: true coordinated_disclosure_text: >- "Do not disclose the vulnerability publicly or to any third parties before it is resolved." advisory_commitment: >- "Once the vulnerability is resolved, we will provide an advisory to our users with details about the issue and the steps taken to address it." safe_harbor: not stated reward: not stated announcements: channel: Slack community url: https://www.pynt.io/community source: SECURITY.md "Security Announcements" note: >- Security announcements are made through the Pynt Slack community channel rather than a status page or a security advisories feed. There is no status.pynt.io (host does not resolve) and no GitHub Security Advisories published on the pynt-io org. security_txt: published: false probes: - url: https://www.pynt.io/.well-known/security.txt status: 404 - url: https://api.pynt.io/.well-known/security.txt status: 404 - url: https://docs.pynt.io/.well-known/security.txt status: 404 note: >- Pynt has a real, findable disclosure policy but does not advertise it at the RFC 9116 location. Publishing a /.well-known/security.txt pointing at the existing SECURITY.md would make it machine-discoverable for zero additional policy work — a notable omission for a company whose product is API security. maintainers: - FN: Kin Lane email: kin@apievangelist.com