generated: '2026-09-04' method: probed source: >- /.well-known/security.txt probes on webscale.com, www.webscale.com, api.webscale.com, control.webscale.com, docs.webscale.com, ai.webscale.com; plus https://www.webscale.com/security/ and https://docs.webscale.com/docs/how-tos/security/ name: Webscale Networks vulnerability disclosure published: false program: none-found security_txt: served: false probes: - host: webscale.com url: https://webscale.com/.well-known/security.txt status: 404 - host: www.webscale.com url: https://www.webscale.com/.well-known/security.txt status: 404 - host: api.webscale.com url: https://api.webscale.com/.well-known/security.txt status: 404 - host: control.webscale.com url: https://control.webscale.com/.well-known/security.txt status: 200 document: false note: >- FALSE POSITIVE, recorded so it is not re-credited. control.webscale.com is a single-page application whose catch-all returns the same 4466-byte HTML console shell for every /.well-known/* path probed — security.txt, openid-configuration, oauth-authorization-server, api-catalog, ai-plugin.json, agent-card.json, agent.json and oauth-protected-resource all returned byte-identical HTML. No RFC 9116 document is served. - host: docs.webscale.com url: https://docs.webscale.com/.well-known/security.txt status: 404 - host: ai.webscale.com url: https://ai.webscale.com/.well-known/security.txt status: 404 bug_bounty: platform: none-found checked: [HackerOne, Bugcrowd, Intigriti] result: no program found disclosure_page: found: false note: >- Webscale publishes a security marketing page (https://www.webscale.com/security/) and a customer how-to section including "What to do in a security breach" (https://docs.webscale.com/docs/how-tos/security/security-breach/), but neither states a responsible-disclosure policy, a security contact address, a safe-harbor statement, or an intake channel for an outside researcher. The breach page is written for a customer whose own store was attacked, not for someone reporting a flaw in Webscale. incident_reporting_for_customers: url: https://docs.webscale.com/docs/how-tos/security/security-breach/ audience: existing customers not_a_vdp: true gap_for_provider: >- A /.well-known/security.txt on www.webscale.com with a Contact and Policy line would be a single-file fix, and would give a researcher who finds something in the platform somewhere to send it. A SOC 2 Type 2 company with no published disclosure channel is the notable asymmetry here.