NEW

Start with the pressure: sales, launch, abuse, agents, data, or guardrails

← All profiles
Automatticcareers logo

Automatticcareers

automattic.com

6
Vendors
3
App matches
7 auth features

Detected Vendor Stack

A
Ashby
ATS / Recruiting
jobs.ashbyhq.com/automattic
75%
vendor customer list
Zendesk
Zendesk
Support
use-automatticcareers.zendesk.com
90%
vendorgraph
Atlassian
Atlassian
Collaboration
use-automatticcareers.atlassian.net
90%
vendorgraph
Auth0
Auth0inferred
CDN / Infra
use-automatticcareers.us.auth0.com
90%
vendorgraph
S
Statuspage
Status Page
use-automatticcareers.statuspage.io
90%
vendorgraph

Our Apps for Your Stack

Enterprise Onboarding

SSO / Identity Provider

No SSO vendor detected for this company. SAML 2.0 and OIDC configuration is available via the enterprise onboarding flow for any compliant IdP.
Authentication features(7 available)
TOTP / Authenticator AppPasskeys (WebAuthn)Magic Link / PasswordlessEncrypted Backup Codes+3 more
TOTP / Authenticator AppPasskeys (WebAuthn)Magic Link / PasswordlessEncrypted Backup CodesJWT API TokensCustom Password Policy· betaOrg-level MFA Enforcement· beta

GitHub Signals

github.com/Automatticprobed Jun 18, 2026
500
Public repos
14
AI repos
46
AI commits / 30d

CI security tooling

garaksemgreptrivysecurity scan

Codebase

LLM frameworkagentic patternsecurity toolingAI governance pagesecurity.md
AI codebase:PHPTypeScriptJavaScriptRubyHTML

AI Attack Surface

AI Subdomain20 signalsobserved 2026-06-23
agent.automattic.com

agent.automattic.com → 192.0.78.24 (+1)

agents.automattic.com

agents.automattic.com → 192.0.78.25 (+1)

ai.automattic.com

ai.automattic.com → 192.0.78.24 (+1)

api.automattic.com

api.automattic.com → 192.0.78.24 (+1)

assistant.automattic.com

assistant.automattic.com → 192.0.78.24 (+1)

chat.automattic.com

chat.automattic.com → 192.0.78.25 (+1)

chatbot.automattic.com

chatbot.automattic.com → 192.0.78.24 (+1)

copilot.automattic.com

copilot.automattic.com → 192.0.78.24 (+1)

genai.automattic.com

genai.automattic.com → 192.0.78.24 (+1)

gpt.automattic.com

gpt.automattic.com → 192.0.78.25 (+1)

inference.automattic.com

inference.automattic.com → 192.0.78.24 (+1)

intelligence.automattic.com

intelligence.automattic.com → 192.0.78.24 (+1)

lab.automattic.com

lab.automattic.com → 192.0.78.25 (+1)

labs.automattic.com

labs.automattic.com → 192.0.78.25 (+1)

llm.automattic.com

llm.automattic.com → 192.0.78.25 (+1)

ml.automattic.com

ml.automattic.com → 192.0.78.25 (+1)

models.automattic.com

models.automattic.com → 192.0.78.25 (+1)

platform.automattic.com

platform.automattic.com → 192.0.78.25 (+1)

playground.automattic.com

playground.automattic.com → 192.0.78.24 (+1)

studio.automattic.com

studio.automattic.com → 192.0.78.24 (+1)

Job Posting Intelligence

25
Total jobs
0
AI security roles
6
Adjacent roles
1
Skill-washed
Hiring patterns detected
Agentic time bomb
Agentic AI in production with no observable AI security tooling
Evidence squeeze
High AI deployment claims but thin audit / governance evidence
Convergence gap
AI and security teams hiring independently with no overlap
1 AI tool in JDs1 framework referenced

Trust Scanner

0

Public Surface

0

AI Language

0

Legal Clarity

0

Security Trust

19

Consistency

100

Remediation Opportunity

Trust Scanner · ATG Scorecard

Automatticcareers · public trust surface

Public trust surface scored 3 with 6 positive detectors out of 74 across 2 pages. Higher remediation scores mean more visible work remains.

3

weak

Public Surface

Whether trust, legal, security, AI, methodology, and contact surfaces are discoverable and coherent.

0

0% signal

AI Language

Whether AI claims are specific, bounded, and tied to engineering evidence rather than generic positioning.

0

0% signal

Legal Clarity

Whether privacy, terms, contract, data-processing, and customer-facing boundaries are clear enough to review.

0

0% signal

Security Trust

Whether public trust artifacts explain controls, evidence, limitations, and escalation paths without oversharing.

0

0% signal

Consistency

Whether public claims, caveats, service language, and trust artifacts agree across the site.

19

19% signal

Remediation Opportunity

Whether the public surface makes the next improvement work obvious, scoped, and evidence-backed.

100

100% signal

Public-signal caveat

Based on public website signals and observed artifacts, not proof of any organization's internal security maturity.

public_claim_with_caveatsurface review

Observed artifacts · 5 of 5

Top finding

high

Missing Secure SDLC

Describe the lifecycle controls that support secure development.

24 more findings
high

Missing Vulnerability Disclosure

Publish the disclosure path and safe-harbor terms together.

high

Missing Security Contact

Expose a clear public security contact or disclosure mailbox.

high

Missing Incident Response

State how incidents are detected, escalated, and communicated.

high

Missing Security Whitepaper

Provide a public security whitepaper when the product depends on trust-sensitive claims.

high

Missing Certifications

Only publish certification claims alongside a public attestation artifact.

high

Missing Security Overview

Add a concise overview of the security program and where the supporting evidence lives.

high

Missing Incident Communication

Document how customers are notified and where public incident updates live.

high

Missing Status Page

Link the status page from the trust surface if it is part of the buyer review path.

high

Missing Privacy Policy

Clarify what personal data you collect, process, retain, and disclose.

high

Missing Privacy Center

Create a single public privacy hub that links policy, rights, and preference actions.

high

Missing Data Subject Request Portal

Expose a public rights-request path for access, deletion, correction, and portability.

high

Missing Consent Management

Clarify how consent is captured, changed, and withdrawn.

high

Missing Data Breach Notice

Explain how breach notification works and who is notified.

high

Missing Data Processing Addendum

Make the DPA request path easy to find for customers and partners.

high

Missing Subprocessors List

Publish a current subprocessor or vendor list with update cadence.

high

Missing AI Usage Policy

Explain how AI is used, reviewed, and bounded in public-facing products.

high

Missing Responsible AI Principles

Publish a short principle set that maps to actual product controls.

high

Missing Customer Data Training Policy

Clarify whether customer prompts, files, and outputs can train or improve models.

high

Missing Model Provider Disclosure

State which model or provider services are used and where customer data may flow.

high

Missing Prompt Logging Policy

Clarify whether prompts, conversations, and outputs are logged or retained.

high

Missing Model Card or System Card

Publish a model or system card if the site makes substantial AI claims.

high

Missing AI Evaluation or Safety Report

Provide a public evaluation or safety summary when AI claims are central.

high

Missing Transparency Report

Publish a public transparency report when the product makes AI capability claims.

high

Missing Model Limitations

Describe where the model or AI system fails, degrades, or needs human review.

Dimension maturity
public surface·Public SurfaceWhether trust, legal, security, AI, and methodology pages are visible and navigable.
ai language·AI LanguageWhether AI claims are specific, bounded, and paired with review or data-use language.
legal clarity·Legal ClarityWhether privacy, terms, DPA, subprocessors, and acceptable-use surfaces are visible.
security trust·Security TrustWhether security, vulnerability, incident-response, and contact paths are documented.
consistency·ConsistencyWhether claims, caveats, and trust artifacts are coherent across pages.
remediation opportunity·Remediation OpportunityWhether the public surface makes the next improvement work obvious.

Scanned 2026-06-23 · rules vtrust-scanner-rules.v1 · 2 artifacts probed