Reqkey Vulnerability Disclosure
ReqKey publishes no vulnerability-disclosure POLICY and runs no bug-bounty program. The only disclosure channel that exists is a single sentence in llms.txt naming support@reqkey.com as the address for, among other things, "security disclosures" — a shared support mailbox, not a security contact with a stated scope, safe-harbour clause or response commitment. Because there is no published policy or dedicated security page, this artifact deliberately does NOT carry a `type: Security` pointer in apis.yml; recording the mailbox as a disclosure program would credit ReqKey with a posture it has not published.
ReqKey publishes a vulnerability disclosure policy for reporting security issues. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.