generated: '2026-08-05' method: searched probe: true source: https://tryriot.com/.well-known/security.txt program: type: coordinated-vulnerability-disclosure platform: Yogosha url: https://app.yogosha.com/cvd/riot-security-inc./14MISime5gRIAGoFZLzCQ4 entity: Riot Security Inc. public_bug_bounty: unknown note: >- The security.txt Contact is a Yogosha CVD submission form rather than a mailto. The Riot security page describes "a bug bounty" alongside annual pentest campaigns but does not name the platform or publish scope/reward tables, so bounty payouts could not be confirmed from public material. contact: - https://app.yogosha.com/cvd/riot-security-inc./14MISime5gRIAGoFZLzCQ4 - security@tryriot.com policy: [] security_page: https://tryriot.com/security/ security_txt: file: well-known/riot-security.txt expires: '2026-08-19T22:00:00.000Z' fields_present: - Contact - Expires fields_missing: - Policy - Encryption - Acknowledgments - Preferred-Languages - Canonical evidence: - source: https://tryriot.com/.well-known/security.txt kind: security.txt (live probe) http_status: 200 - source: https://tryriot.com/security/ kind: security page http_status: 200 found: - bug bounty - annual pentest campaigns - security@tryriot.com gaps: - No `Policy:` field in security.txt — the disclosure terms are not linked from the machine-readable file. - security.txt `Expires` falls two weeks after this probe and will go stale without rotation.