generated: '2026-08-02' method: probed probe: true published: false description: >- No vulnerability disclosure program, security policy page, or security contact could be found on any anonymous VideoAmp surface. Recorded as a verified absence rather than omitted, so a later round can detect the change if VideoAmp publishes one. policy: [] contact: [] bug_bounty: platform: null url: null probes: - {url: 'https://videoamp.com/.well-known/security.txt', http_status: 404} - {url: 'https://videoamp.com/security.txt', http_status: 404} - {url: 'https://api.videoamp.dev/.well-known/security.txt', http_status: 404} - {url: 'https://login.videoamp.com/.well-known/security.txt', http_status: 404} - {url: 'https://videoamp.com/security/', http_status: 404} - {url: 'https://videoamp.com/responsible-disclosure/', http_status: 404} - {url: 'https://videoamp.com/vulnerability-disclosure/', http_status: 404} - {url: 'https://videoamp.com/security/responsible-disclosure', http_status: 404} - {url: 'https://hackerone.com/videoamp', http_status: 404} - {url: 'https://bugcrowd.com/videoamp', http_status: 404} - {url: 'https://trust.videoamp.com/.well-known/security.txt', http_status: 200, valid: false, note: 'SPA catch-all HTML, not RFC 9116 text.'} notes: - >- A Vanta trust center exists at https://trust.videoamp.com/ and may host a disclosure policy behind its client-rendered UI, but nothing is reachable anonymously. - >- The only published contact address is the general support address support@videoamp.com, cited in the API documentation shipped with the VideoAmp CLI. It is a support channel, not a security contact, and is not recorded as one here. x-evidence: fetched: '2026-08-02'