generated: '2026-09-17' method: probed source: >- probe of /.well-known/security.txt on every Seismic host, the trust center at https://trust.seismic.com/ , and a search of HackerOne / Bugcrowd / Intigriti for a Seismic program published: false description: >- Seismic publishes NO coordinated vulnerability disclosure policy that we could find. Recorded as a measured absence, not an unchecked field — every probe below was run on 2026-09-17. probes: - url: https://seismic.com/.well-known/security.txt status: 404 - url: https://www.seismic.com/.well-known/security.txt status: 404 - url: https://api.seismic.com/.well-known/security.txt status: 404 - url: https://auth.seismic.com/.well-known/security.txt status: 404 - url: https://developer.seismic.com/.well-known/security.txt status: 200 verdict: not-a-document detail: >- The ReadMe docs host returns its 1.8MB single-page-app HTML shell for this and every other unmatched path. Not a security.txt. - url: https://status.seismic.com/.well-known/security.txt status: 200 verdict: third-party detail: >- A real, PGP-signed security.txt — but ATLASSIAN's, served by the Statuspage that hosts status.seismic.com (Canonical https://www.atlassian.com/.well-known/security.txt, Contact security@atlassian.com). It says nothing about Seismic's own disclosure posture and is deliberately not credited to Seismic. - url: https://trust.seismic.com/ status: 403 verdict: live-but-challenged detail: >- SafeBase trust center behind a Cloudflare interactive challenge. Read on 2026-09-17: it lists certifications (SOC 2 Type 2, ISO/IEC 27001:2022, 27701:2019, 42001:2023, GDPR, CCPA, EU-US DPF, APEC CBPR, WCAG) but names no vulnerability reporting process or contact. bug_bounty: program: false platforms_checked: [HackerOne, Bugcrowd, Intigriti] detail: No public Seismic Software program found on any of the three. security_contact: found: true address: security@seismic.com where: >- Declared in DNS, not on the web: the seismic.com CAA record carries `0 iodef "mailto:security@seismic.com"` (see security/seismic-domain-security.yml). That is a certificate-authority incident-reporting address under RFC 8659, and it is the only machine-readable security contact Seismic publishes. It is NOT a disclosure policy: there is no stated scope, no safe-harbour language, and no response commitment. finding: >- For a vendor holding SOC 2 Type 2, three ISO certifications and an enterprise customer base, the absence of a security.txt and a published disclosure policy is the cheapest gap on this profile to close: an RFC 9116 file at https://seismic.com/.well-known/security.txt pointing at the address already in their CAA record would settle it.