generated: '2026-09-02' method: probed probe: true source: https://developer.unico.io/.well-known/security.txt note: >- Re-written after probe-security-programs.py, which had reduced this file to the two fields it parses out of security.txt (and mis-parsed the Policy field, whose value here is free text beginning with "#" rather than a URI). The richer probe record is retained. program: type: public bug bounty platform: HackerOne url: https://hackerone.com/unico_idtech http_status: 200 public: true contact: - mailto:gestaodevulnerabilidades@unico.io - https://hackerone.com/unico_idtech policy: standard: ISO 29147 statement: >- "Any submission made to Unico ID is subject to the Vulnerability Disclosure Policy based on ISO 29147. To ensure compliance with the standard please review it before submitting. Our HackerOne program is public — you can report directly at https://hackerone.com/unico_idtech" published_page: null rfc9116_deviation: >- The Policy field carries prose rather than a URI, so an RFC 9116 parser reads it as an invalid value. The policy document itself is not published at a linkable URL. security_txt: served: true hosts: - host: developer.unico.io url: https://developer.unico.io/.well-known/security.txt http_status: 200 file: ../well-known/unico-security.txt expires: '2026-12-31T11:59:59Z' contacts: [https://hackerone.com/unico_idtech] - host: api.id.unico.app url: https://api.id.unico.app/.well-known/security.txt http_status: 200 file: ../well-known/unico-api-security.txt expires: '2026-12-31T23:59:59Z' contacts: [mailto:gestaodevulnerabilidades@unico.io, https://hackerone.com/unico_idtech] - host: identity.acesso.io url: https://identity.acesso.io/.well-known/security.txt http_status: 200 expires: '2026-12-31T23:59:59Z' contacts: [mailto:gestaodevulnerabilidades@unico.io, https://hackerone.com/unico_idtech] preferred_languages: [en, es, pt] variant_note: >- Two variants are served. The developer-portal copy omits the mailto and expires twelve hours earlier than the other two. Both are unexpired as of the probe date. evidence: - url: https://developer.unico.io/.well-known/security.txt status: 200 - url: https://api.id.unico.app/.well-known/security.txt status: 200 - url: https://identity.acesso.io/.well-known/security.txt status: 200 - url: https://hackerone.com/unico_idtech status: 200