generated: '2026-08-28' method: searched source: >- https://www.smartersorting.com/security-ai-governance (HTTP 200); probes of /.well-known/security.txt on api.smartersorting.com (404), www.smartersorting.com (404), api.smarterx.com (404) and data.smartersorting.com (404). program_published: false security_contact: security@smartersorting.com contact_source: https://www.smartersorting.com/security-ai-governance security_txt: false bug_bounty: platform: null found: false checked: - HackerOne - Bugcrowd - Intigriti disclosure_policy_url: null note: >- Smarter Sorting publishes a named security contact address (security@smartersorting.com) on its security and AI governance page, which is a real, usable reporting channel. It does NOT publish a vulnerability disclosure policy, safe-harbour language, a response-time commitment, a bug bounty, or a /.well-known/security.txt on any host — so a researcher has an address but no stated terms. The single highest-value, lowest-effort fix available to this provider is to serve a security.txt at https://www.smartersorting.com/.well-known/security.txt carrying Contact: and Policy: fields.