Leena AI · Vulnerability Disclosure

Leena Ai Vulnerability Disclosure

Vulnerability disclosure

Leena AI runs a coordinated vulnerability disclosure program on Hackerone.

CompanyAi MlAgentic AIArtificial IntelligenceEnterprise SoftwareHuman ResourcesIT Service ManagementEmployee ExperienceWorkflow AutomationConversational AIModel Context ProtocolKnowledge Management
Program: Hackerone

Disclosure Policy

Policy
Policy
Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-07-19'
method: searched
sources:
  - https://leena.ai/.well-known/security.txt
  - https://trust.leena.ai/
summary: >-
  Leena AI operates a responsible disclosure programme, advertised through an RFC 9116
  security.txt on its primary host with a named security mailbox and a policy pointer into
  its trust center. There is no public bug bounty on HackerOne, Bugcrowd or Intigriti, and
  no safe-harbour statement or published response SLA.
security_txt:
  url: https://leena.ai/.well-known/security.txt
  status: 200
  file: leena-ai-security.txt
  fields:
    Contact: mailto:security@leena.ai
    Expires: '2027-05-27T00:00:00.000Z'
    Policy: 'https://trust.leena.ai/?itemUid=bda1002e-a52c-4a7f-a640-95a72fa64eda'
    Preferred-Languages: en
    Canonical: https://leena.ai/.well-known/security.txt
  valid: true
  expired: false
contacts:
  - email: security@leena.ai
    source: security.txt Contact
    role: primary security contact
  - email: isg@leena.ai
    source: https://trust.leena.ai/
    role: responsible disclosure reporting address (Information Security Group)
policy:
  url: 'https://trust.leena.ai/?itemUid=bda1002e-a52c-4a7f-a640-95a72fa64eda'
  published: true
  note: >-
    Leena AI states that full vulnerability-management policy documentation is not shared
    externally; the SOC 2 Type 2 report provides the procedural detail instead.
bug_bounty:
  program: false
  platforms_checked:
    - HackerOne
    - Bugcrowd
    - Intigriti
  result: no public programme found
  rewards: none published
safe_harbor:
  published: false
response_sla:
  published: false
encryption:
  pgp_key: null
  note: No Encryption field is present in security.txt.
gaps:
  - No safe-harbour / legal-protection statement for researchers.
  - No published response or triage SLA.
  - No PGP key (security.txt has no Encryption field).
  - security.txt is not served from any API host, only the marketing host.
  - Two different reporting addresses are advertised (security@ in security.txt, isg@ in the trust center).