Bardeen Vulnerability Disclosure
Bardeen publishes a named security contact for vulnerability reports on its security page. There is no formal disclosure policy, no safe-harbour statement, no stated response or remediation window, and no bug bounty program — probed HackerOne, Bugcrowd and Intigriti plus the company's own hosts on 2026-08-29. The contact is human-readable only: /.well-known/security.txt returns 404 on www.bardeen.ai, bardeen.ai and www.getwiq.ai, so no automated scanner or agent can discover it. A two-line RFC 9116 file would close that gap without any policy work.
Bardeen runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.