generated: '2026-08-14' method: searched probe: true source: https://app.voiceops.com/.well-known/security.txt policy: [] policy_note: >- The security.txt carries no Policy: field, so VoiceOps publishes a security contact but not a written vulnerability-disclosure policy. No bug bounty program was found on HackerOne, Bugcrowd or Intigriti, and no /security, /responsible-disclosure or /vulnerability-disclosure page exists on voiceops.com (all return HTTP 404). contact: - mailto://engineering@voiceops.com security_txt: url: https://app.voiceops.com/.well-known/security.txt file: well-known/voiceops-security.txt spec: RFC 9116 http_status: 200 content_type: text/plain last_modified: '2026-08-13' fields: contact: mailto://engineering@voiceops.com expires: '2028-03-01T07:01:00.000Z' preferred_languages: en canonical: https://app.voiceops.com/.well-known/security.txt deviations: - >- Contact uses the non-standard scheme form "mailto://" rather than the RFC 6068 "mailto:" form; strict RFC 9116 parsers may reject it. - >- Served only from app.voiceops.com. RFC 9116 expects the file at the organization's primary domain — voiceops.com/.well-known/security.txt returns 404 — so a researcher starting at the company's public website will not find it. - 'No Policy:, Encryption:, Acknowledgments: or Hiring: fields.' evidence: - source: https://app.voiceops.com/.well-known/security.txt kind: security.txt http_status: 200 detail: RFC 9116 document, 162 bytes, text/plain, served via S3/CloudFront; Contact mailto://engineering@voiceops.com - source: well-known/voiceops-security.txt kind: security.txt (harvested verbatim) - source: https://voiceops.com/.well-known/security.txt kind: security.txt http_status: 404 detail: Not served on the primary domain. - source: https://www.voiceops.com/security kind: disclosure-page http_status: 404 detail: No security or responsible-disclosure page on the marketing site.