generated: '2026-08-05' method: probed probe: true found: false description: >- Read AI publishes NO vulnerability disclosure program. This file records the absence, with the probes that establish it — it is a gap the provider can close cheaply (an RFC 9116 security.txt plus a /security disclosure page), not a scoring penalty invented by API Evangelist. No Security pointer is emitted in apis.yml because there is nothing to point at. policy: [] contact: [] bug_bounty: null security_txt: null evidence: - {url: 'https://www.read.ai/.well-known/security.txt', http_status: 404, note: 'Marketing host returns an "Invalid .well-known request" page.'} - {url: 'https://api.read.ai/.well-known/security.txt', http_status: 404} - {url: 'https://www.read.ai/security', http_status: 404} - {url: 'https://www.read.ai/security-policy', http_status: 404} - {url: 'https://www.read.ai/responsible-disclosure', http_status: 404} - {url: 'https://www.read.ai/vulnerability-disclosure', http_status: 404} - {url: 'https://hackerone.com/read_ai', http_status: 404} - {url: 'https://hackerone.com/readai', http_status: 404} - {url: 'https://bugcrowd.com/read-ai', http_status: 404} nearest_available_channel: description: >- Read AI's Security & Privacy Overview directs security and compliance questions to the Trust Center and to general support; it names no security@ address and no coordinated-disclosure process. urls: - https://trust.read.ai/ - https://support.read.ai/hc/en-us/articles/25702259763091-Security-Privacy-Overview x-evidence: fetched: '2026-08-05' method: anonymous HTTP GET