generated: '2026-08-13' method: probed source: >- probe-security-programs.py + live probes of /.well-known/security.txt on api.spredfast.com, login.spredfast.com, spredfast.com, developer.khoros.com; plus https://khoros.ai/trust-center/ program: none note: >- NO published vulnerability disclosure program. There is no security.txt on any Spredfast or Khoros host, no /security/disclosure or /responsible-disclosure page, and no HackerOne, Bugcrowd or Intigriti listing. The Khoros trust center names six compliance certifications but gives no security-reporting address — it routes enquiries through a customer success manager or the khoros.ai/lets-connect/ contact form. The nearest published mailbox is compliance@khoros.com, which is a compliance contact, not a disclosure channel. Because there is no program, NO `type: Security` pointer is emitted for this provider. security_txt: false bug_bounty: false disclosure_page: false security_contact: null evidence: - url: https://api.spredfast.com/.well-known/security.txt status: 401 - url: https://login.spredfast.com/.well-known/security.txt status: 404 - url: https://spredfast.com/.well-known/security.txt status: 503 - url: https://developer.khoros.com/.well-known/security.txt status: 200 note: >- Soft 200 — the ReadMe SPA HTML shell, served identically for every path. Not a security.txt. - url: https://khoros.ai/trust-center/ status: 200 note: Trust center present; names certifications but no disclosure program or security contact. related: security/spredfast-trust-center.yml