generated: '2026-09-19' method: searched probe: true source: https://thehiveryiq.com/.well-known/security.txt docs: https://thehiveryiq.com/security/ policy: - https://thehiveryiq.com/security/ contact: - mailto:security@thehiveryiq.com security_txt: url: https://thehiveryiq.com/.well-known/security.txt file: well-known/thehiveryiq-com-security.txt fields: Contact: mailto:security@thehiveryiq.com Expires: '2027-05-08T00:00:00Z' Preferred-Languages: en Canonical: https://thehiveryiq.com/.well-known/security.txt Policy: https://thehiveryiq.com/security/ second_file: https://hive-mcp-gateway.onrender.com/.well-known/security.txt (Contact steve@thehiveryiq.com, Policy https://www.thehiveryiq.com) program: type: coordinated disclosure, no bounty scope: 'In scope: thehiveryiq.com and all subdomains, Hive API endpoints, Cloudflare Workers serving hive-signed receipts, Hivemorph admin panel. Out of scope: third-party sub-processors, social engineering, denial-of-service testing, automated scanning without prior approval.' encryption: PGP key available on request at the contact address timeline: acknowledgement: to be confirmed triage: to be confirmed remediation_target: 30 days for critical; 90 days for medium/low public_disclosure: 90-day window from report receipt; extensions by mutual agreement rewards: '"We do not offer monetary bounties at this time." Public acknowledgement, coordinated disclosure and a letter of commendation for valid critical findings; a Hall of Fame table exists with no entries yet.' bug_bounty_platform: null evidence: - source: https://thehiveryiq.com/.well-known/security.txt kind: security.txt (live probe) http_status: 200 fetched: '2026-09-19' - source: https://thehiveryiq.com/security/ kind: Vulnerability Disclosure section (searched) http_status: 200 fetched: '2026-09-19' quote: Hive Civilization welcomes security researchers. We commit to a fair, transparent disclosure process.