generated: '2026-09-05' method: searched source: https://solsten.io/data-privacy name: Solsten vulnerability disclosure summary: >- Solsten publishes a security contact address but not a vulnerability disclosure program. There is no /.well-known/security.txt on any host, no disclosure policy page, no safe-harbour statement, and no bug bounty on HackerOne, Bugcrowd or Intigriti. What exists is a single line on the Data Privacy page directing security questions to a named mailbox. program: none policy_url: null security_txt: false safe_harbor: false bug_bounty: present: false platform: null contacts: - type: email value: security@solsten.io context: >- "Questions — For any question, please do not hesitate to reach out to security@solsten.io." Published in the Questions section of the Data Privacy page. evidence: https://solsten.io/data-privacy practices_claimed: - claim: >- "Penetration test and / or code review ('Security Check') once a year or after any major change in the system by external organization" evidence: https://solsten.io/data-privacy note: A stated internal practice, not a published report or attestation. evidence: - url: https://solsten.io/data-privacy status: 200 - url: https://solsten.io/.well-known/security.txt status: 404 - url: https://www.solsten.io/.well-known/security.txt status: 404 - url: https://api.solsten.io/.well-known/security.txt status: 404 - url: https://docs.api.solsten.io/.well-known/security.txt status: 404 - url: https://solsten.io/security status: 404 gaps: - No RFC 9116 security.txt on any host — the machine-readable form of exactly the contact they already publish. - No disclosure policy, response-time commitment, or safe-harbour language. - The security contact is buried in a privacy page rather than surfaced on a security page.