Artificial Labs · Vulnerability Disclosure

Artificial Labs Vulnerability Disclosure

Vulnerability disclosure

Artificial Labs runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

InsuranceUnited KingdomInsurtechUnderwritingReinsuranceSpecialty InsuranceLondon MarketLloyd's of LondonBrokerPolicy AdministrationACORDAlgorithmic Underwriting
Program: Hackerone

Disclosure Policy

Policy

Security Contact

Contact
privacy@artificial.io

Source

Vulnerability Disclosure

artificial-labs-vulnerability-disclosure.yml Raw ↑
generated: '2026-07-25'
method: searched
probe: true
note: |
  Artificial Labs publishes a real, substantive security page and a Vanta trust
  center, but no RFC 9116 security.txt, no bug bounty and no named responsible
  disclosure programme. The only disclosure route the company publishes is the
  instruction in its Acceptable Use Policy (last updated 26 March 2026, carried
  on the security page) to report a suspected security breach, data leak or
  unauthorised account access by email. That is recorded here as the disclosure
  contact because it is the only one that exists — it is a customer-obligation
  clause, not a researcher-facing VDP.
policy:
- https://artificial.io/security/
contact:
- privacy@artificial.io
bug_bounty:
  program: none found
  platforms_checked: [HackerOne, Bugcrowd, Intigriti]
security_txt:
  present: false
  probes:
  - url: https://artificial.io/.well-known/security.txt
    status: 404
  - url: https://www.artificial.io/.well-known/security.txt
    status: 301
  - url: https://docs.artificial.io/.well-known/security.txt
    status: 302
    note: Redirects to the Auth0 login like every gated path on the documentation host.
pages_checked:
- url: https://artificial.io/security/
  status: 200
  note: ISO 27001 and Cyber Essentials Plus, encryption, access control, penetration
    testing and the Acceptable Use Policy with the breach-reporting instruction.
- url: https://trust.artificial.io/
  status: 200
  note: Vanta trust center (client-rendered).
- url: https://security.artificial.io/
  status: 0
  note: No DNS record.
evidence:
- source: https://artificial.io/security/
  kind: security page
  quote: Tell us immediately if you suspect a security breach, a data leak, or unauthorised
    access to or use of any account by sending notice to privacy@artificial.io.
gaps:
- No /.well-known/security.txt.
- No public vulnerability disclosure policy or safe-harbour statement for researchers.
- No bug bounty programme on any major platform.