Edge Impulse Vulnerability Disclosure
Edge Impulse publishes NO coordinated vulnerability disclosure program. There is no security.txt on any host, no /security/disclosure or /responsible-disclosure page, no first-party SECURITY.md in the GitHub organization (all 73 SECURITY.md hits there are vendored third-party files — ARM Ethos core driver, STMicroelectronics STM32Cube middleware — not Edge Impulse policy), and no HackerOne, Bugcrowd or Intigriti listing. The public security page is a SOC 2 compliance narrative with a Contact Sales button — it names no security contact, no reporting address and no safe-harbour language. A researcher who finds a flaw in the Studio API has no published route to report it. This is the clearest fixable gap in the Edge Impulse security posture; a single RFC 9116 security.txt would close it.
Edge Impulse runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.