generated: '2026-08-26' method: probed source: >- /.well-known/security.txt probed on all eight Pypestream hosts, plus searches for a Pypestream bug bounty or coordinated disclosure programme (2026-08-26) published: false security_txt: rfc9116: false hosts_probed: 8 hits: 1 hit_note: >- The single 200 is not Pypestream's. analytics.pypestream.com/.well-known/security.txt serves PostHog's unmodified upstream file -- Contact mailto:engineering@posthog.com, Hiring https://posthog.com/careers, Expires 2024-03-14 (more than two years stale). It is an artifact of Pypestream self-hosting PostHog for its Analytics product, and it directs any would-be reporter to a third party rather than to Pypestream. Saved verbatim at well-known/pypestream-analytics-security.txt. bug_bounty: programme: null platforms_checked: [HackerOne, Bugcrowd, Intigriti] found: false disclosure_policy: url: null found: false security_contact: published: null note: >- No security@ address, no disclosure page and no vulnerability-reporting route is published on pypestream.ai, pypestream.com or developers.pypestream.com. The developer portal's authentication page routes security questions to "your Pypestream Success Manager" -- an account-managed channel available only to existing customers, not a public disclosure path. The only public inbound channels are the Atlassian service desk at https://support.pypestream.com/ and the /demo sales form. gap: >- A researcher outside the customer base has no published way to report a vulnerability to Pypestream, and the one security.txt an automated scanner will find on a Pypestream host points at PostHog.