generated: '2026-08-14' method: searched probe: true source: https://www.regal.ai/security policy: [] policy_published: false contact: - security@regal.ai - security@regal.io bug_bounty: null security_txt: false security_txt_note: >- /.well-known/security.txt (RFC 9116) is not served on any Regal host: www.regal.ai and developer.regal.ai return 404, api.regal.ai returns 403 "Missing Authentication Token", events.regalvoice.com returns 403 "Forbidden", and app.regal.io answers 200 with an SPA HTML shell for every /.well-known/* path (not a document). https://www.regal.ai/security.txt is also 404. note: >- Regal publishes a security and compliance page with a named security contact, and a Trust Center at https://trust.regal.ai, but NO responsible-disclosure or vulnerability-disclosure policy, no bug-bounty program (no HackerOne / Bugcrowd / Intigriti presence found), and no security.txt. A researcher has an address to write to and no published terms, scope, or response commitment. The security page states: "Looking for more information? See our Privacy Policy, Data Processing Addendum or email us at security@regal.ai" — the mailto on that page resolves to security@regal.io, the legacy corporate domain. evidence: - {source: 'https://www.regal.ai/security', kind: security-page, http_status: 200, found: [security@regal.ai, 'mailto:security@regal.io', SOC2, GDPR, CCPA]} - {source: 'https://trust.regal.ai', kind: trust-center, http_status: 200, found: [Regal Trust Center]} - {source: 'https://www.regal.ai/.well-known/security.txt', kind: security.txt, http_status: 404} - {source: 'https://developer.regal.ai/.well-known/security.txt', kind: security.txt, http_status: 404} - {source: 'https://api.regal.ai/.well-known/security.txt', kind: security.txt, http_status: 403} - {source: 'https://www.regal.ai/security.txt', kind: security.txt, http_status: 404} gaps: - No published vulnerability disclosure policy or safe-harbour statement. - No bug bounty program. - No /.well-known/security.txt. - The published contact spans two domains (regal.ai and regal.io) without a canonical statement of which is authoritative.