Regal · Vulnerability Disclosure

Regal Ai Vulnerability Disclosure

Vulnerability disclosure

Regal runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

Artificial IntelligenceAI AgentsVoice AIContact CenterOutbound CallingInbound CallingPhone AgentsSMSChatWebRTCConversation IntelligenceJourney OrchestrationBranded Caller IDCCaaSCPaaSSales DialerCustomer Engagement
Program: Hackerone security.txt present

Disclosure Policy

Security Contact

Contact
security@regal.ai
Contact
security@regal.io

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-14'
method: searched
probe: true
source: https://www.regal.ai/security
policy: []
policy_published: false
contact:
  - security@regal.ai
  - security@regal.io
bug_bounty: null
security_txt: false
security_txt_note: >-
  /.well-known/security.txt (RFC 9116) is not served on any Regal host: www.regal.ai and
  developer.regal.ai return 404, api.regal.ai returns 403 "Missing Authentication Token",
  events.regalvoice.com returns 403 "Forbidden", and app.regal.io answers 200 with an SPA
  HTML shell for every /.well-known/* path (not a document). https://www.regal.ai/security.txt
  is also 404.
note: >-
  Regal publishes a security and compliance page with a named security contact, and a Trust
  Center at https://trust.regal.ai, but NO responsible-disclosure or vulnerability-disclosure
  policy, no bug-bounty program (no HackerOne / Bugcrowd / Intigriti presence found), and no
  security.txt. A researcher has an address to write to and no published terms, scope, or
  response commitment. The security page states: "Looking for more information? See our
  Privacy Policy, Data Processing Addendum or email us at security@regal.ai" — the mailto on
  that page resolves to security@regal.io, the legacy corporate domain.
evidence:
  - {source: 'https://www.regal.ai/security', kind: security-page, http_status: 200, found: [security@regal.ai, 'mailto:security@regal.io', SOC2, GDPR, CCPA]}
  - {source: 'https://trust.regal.ai', kind: trust-center, http_status: 200, found: [Regal Trust Center]}
  - {source: 'https://www.regal.ai/.well-known/security.txt', kind: security.txt, http_status: 404}
  - {source: 'https://developer.regal.ai/.well-known/security.txt', kind: security.txt, http_status: 404}
  - {source: 'https://api.regal.ai/.well-known/security.txt', kind: security.txt, http_status: 403}
  - {source: 'https://www.regal.ai/security.txt', kind: security.txt, http_status: 404}
gaps:
  - No published vulnerability disclosure policy or safe-harbour statement.
  - No bug bounty program.
  - No /.well-known/security.txt.
  - The published contact spans two domains (regal.ai and regal.io) without a canonical statement of which is authoritative.