Aignostics · Vulnerability Disclosure
Aignostics Vulnerability Disclosure
Vulnerability disclosure
Aignostics runs a coordinated vulnerability disclosure program on Hackerone.
CompanyArtificial IntelligenceMachine-LearningHealthHealthcareLife SciencesPathologyMedical ImagingDigital PathologyOncologyBiotechnologyResearchGermany
Program: Hackerone
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
generated: '2026-09-14'
method: searched
source: https://aignostics.readthedocs.io/en/latest/security.html
scope: >-
The published policy covers the Aignostics Python SDK (the open-source client), not explicitly the
Aignostics Platform service. No separate platform-level disclosure policy was found.
program:
published: true
url: https://aignostics.readthedocs.io/en/latest/security.html
http_status: 200
intake:
- channel: github-security-advisory
url: https://github.com/aignostics/python-sdk/security/advisories/new
http_status: 200
note: >-
Private vulnerability reporting is enabled on the repository, which is the intake the policy
names first.
- channel: email
address: helmut@aignostics.com
note: >-
A named individual rather than a role address. security@aignostics.com was not published and
no /.well-known/security.txt is served on any Aignostics host.
commitments:
- confirm receipt of the report
- investigate
- fix
- release a security update
response_sla: not stated
safe_harbor: not stated
bug_bounty:
exists: false
detail: >-
No HackerOne, Bugcrowd, Intigriti or self-hosted bounty program was found; the policy does not
mention rewards.
supported_versions:
statement: We currently provide security updates for the latest minor version.
scope: Aignostics Python SDK
security_txt:
served: false
probed:
- url: https://www.aignostics.com/.well-known/security.txt
status: 404
- url: https://aignostics.com/.well-known/security.txt
status: 404
- url: https://platform.aignostics.com/.well-known/security.txt
status: 307
note: Auth0 session gate; no anonymous document
- url: https://aignostics.readthedocs.io/.well-known/security.txt
status: 404
note: >-
A one-line RFC 9116 file on www.aignostics.com pointing Policy: at the existing security.html and
Contact: at the existing mailbox would make this program machine-discoverable at zero cost. The
program already exists; only the pointer is missing.
supply_chain_practice:
source: >-
https://aignostics.readthedocs.io/en/latest/security.html,
https://aignostics.readthedocs.io/en/latest/operational_excellence.html
controls:
- Dependabot
- Renovate
- GitHub CodeQL
- SonarQube
- secret detection
- pip-audit
- trivy
- SBOM generation
note: >-
Unusually complete for a company of this size, and published rather than asserted - the CI
configuration backing these claims is in the public repository.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/aignostics-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.