Akuity · Vulnerability Disclosure

Akuity Vulnerability Disclosure

Vulnerability disclosure

Akuity runs a stated responsible-disclosure program with a named security contact, published on its Security and Compliance page. It does NOT publish an RFC 9116 security.txt, a bug-bounty program, or a dedicated disclosure policy page with scope and safe-harbour terms.

Akuity runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

GitOpsContinuous DeliveryKubernetesArgo CDKargoPlatform EngineeringDevOpsProgressive DeliveryCloud NativeAIOpsDeveloper Tools
Program: Hackerone

Disclosure Policy

Security Contact

Contact
mailto:security@akuity.io
Contact
mailto:security+ssl@akuity.io

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-06'
method: searched
source: https://akuity.io/security-compliance
description: >-
  Akuity runs a stated responsible-disclosure program with a named security
  contact, published on its Security and Compliance page. It does NOT publish an
  RFC 9116 security.txt, a bug-bounty program, or a dedicated disclosure policy
  page with scope and safe-harbour terms.

program:
  exists: true
  type: responsible-disclosure
  statement: >-
    "Akuity encourages responsible disclosure of security vulnerabilities.
    Security contact: security@akuity.io. Reported issues are reviewed, triaged,
    and addressed according to internal procedures."
  policy_page: https://akuity.io/security-compliance

contact:
  - mailto:security@akuity.io
  - mailto:security+ssl@akuity.io   # CAA iodef record on akuity.cloud

bug_bounty:
  exists: false
  platforms_checked: [HackerOne, Bugcrowd, Intigriti]

security_txt:
  exists: false
  probes:
    - url: https://akuity.io/.well-known/security.txt
      status: 404
    - url: https://akuity.io/security.txt
      status: 404
    - url: https://akuity.cloud/.well-known/security.txt
      status: 404
    - url: https://docs.akuity.io/.well-known/security.txt
      status: 404
    - url: https://trust.akuity.io/.well-known/security.txt
      status: 200
      verdict: false-positive
      note: Vanta SPA catch-all — control path returned identical HTML with 200.
    - url: https://status.akuity.io/.well-known/security.txt
      status: 200
      verdict: vendor-not-provider
      note: 'Atlassian Statuspage''s own file; Canonical: https://www.atlassian.com/.well-known/security.txt'
  checked: '2026-08-06'

vulnerability_management:
  source: https://akuity.io/security-compliance
  practices:
    - Regular vulnerability scanning of public-facing assets
    - Risk-based remediation timelines
    - Periodic third-party penetration testing
    - Verification and tracking of remediation efforts
    - Dependency scanning and vulnerability detection in CI/CD
  customer_sla: >-
    "CVE notifications and SLA on resolution" is an Enterprise-plan feature —
    a contractual remediation SLA, not a published one.
  supply_chain:
    signed_images: https://docs.akuity.io/akuity-portal/security/verifying-images
    distroless_report: https://docs.akuity.io/akuity-portal/security/distroless_report

incident_response:
  documented: true
  statement: >-
    "Documented incident response plan. Defined escalation and communication
    procedures. Customers are notified of security incidents in accordance with
    contractual and regulatory obligations."

gap:
  note: >-
    A one-line email contact on a marketing-adjacent page is the weakest form of
    a disclosure program. Publishing an RFC 9116 /.well-known/security.txt on
    akuity.io and akuity.cloud — pointing at that same security@akuity.io and a
    policy page with scope and safe-harbour terms — would be a small change with
    a real effect on how quickly a researcher reaches the right team.

evidence:
  - source: https://akuity.io/security-compliance
    kind: published responsible-disclosure statement
    fetched: '2026-08-06'
    http_status: 200
  - source: dig CAA akuity.cloud
    kind: 'CAA iodef record: 0 iodef "mailto:security+ssl@akuity.io"'
    fetched: '2026-08-06'