generated: '2026-08-05' method: searched source: https://www.soci.ai/information-security/ probe: true program: type: bug-bounty name: SOCi Security Bug Bounty Program scope: SOCi systems and applications public_policy_document: false note: >- SOCi publicly states it "runs a Security Bug Bounty Program for our systems and applications" and invites reporters to make contact by email. There is no published scope/rules document, no safe-harbor language, no reward table, and no listing on HackerOne, Bugcrowd or Intigriti that could be found. Intake is an email address only. policy: - https://www.soci.ai/information-security/ - https://trust.meetsoci.com/ contact: - security@soci.ai - security@meetsoci.com security_txt: published: false note: >- /.well-known/security.txt returns 404 on both www.soci.ai and www.meetsoci.com — see well-known/soci-well-known.yml. Publishing an RFC 9116 security.txt pointing at the information-security page would make this program machine-discoverable. evidence: - source: https://www.soci.ai/information-security/ status: 200 kind: security-page keywords: - security bug bounty program - responsible disclosure - soc 2 - iso 27001 - source: https://trust.meetsoci.com/ status: 200 kind: trust-center keywords: - vulnerability - security@meetsoci.com - source: https://www.soci.ai/.well-known/security.txt status: 404 kind: security.txt x-evidence: fetched: '2026-08-05' note: >- The bug-bounty contact address on the information-security page is obfuscated with Cloudflare email protection; it decodes to security@soci.ai. The security@meetsoci.com address is published on the SafeBase trust center.