generated: '2026-08-13' method: searched probe: true source: https://samu.ai/politica-de-seguridad-y-manejo-de-informacion policy: - https://samu.ai/politica-de-seguridad-y-manejo-de-informacion contact: - security@samu.ai security_txt: false bug_bounty: false formal_disclosure_program: false note: >- Samu publishes a security policy page ("Politica de seguridad y manejo de informacion") that names a security contact, security@samu.ai, and describes encryption (AES at rest, TLS in transit), subprocessors and the AICPA SOC seal. It does NOT describe a responsible-disclosure or vulnerability-reporting process, there is no bug bounty (no HackerOne/Bugcrowd/Intigriti presence found) and /.well-known/security.txt returns 404 on every Samu host. A researcher has a named mailbox to write to but no published intake process, scope or safe-harbour terms. evidence: - source: https://samu.ai/politica-de-seguridad-y-manejo-de-informacion http_status: 200 kind: security-policy-page found: [security@samu.ai, 'AICPA SOC for service organizations', AES, TLS] - source: https://samu.ai/.well-known/security.txt http_status: 404 kind: security.txt - source: https://api.samu.ai/.well-known/security.txt http_status: 404 kind: security.txt