generated: '2026-08-09' method: searched probe: true source: https://www.1lookup.io/security description: >- 1Lookup publishes a security page with a named security contact and a documented incident-response plan, and invites reports via a "Report Security Issue" action. It does NOT publish an RFC 9116 security.txt, a formal vulnerability-disclosure policy, safe-harbour terms, or a bug bounty program — so this is a security contact, not a VDP. Recorded as found, with the gap named. policy: [] policy_url: https://www.1lookup.io/security contact: - security@1lookup.io report_channel: '"Report Security Issue" action on https://www.1lookup.io/security' bug_bounty: present: false platforms_checked: [HackerOne, Bugcrowd, Intigriti] security_txt: present: false probed: - {url: 'https://www.1lookup.io/.well-known/security.txt', status: 404} - {url: 'https://1lookup.io/.well-known/security.txt', status: 404} - {url: 'https://app.1lookup.io/.well-known/security.txt', status: 200, note: 'text/html SPA shell, not RFC 9116'} incident_response: documented: true plan: 24/7 monitoring with automated response playbooks published_targets: detection: < 5 minutes assessment: < 15 minutes containment: < 30 minutes resolution: < 2 hours source: https://www.1lookup.io/security evidence: - {source: 'https://www.1lookup.io/security', kind: security-page, keywords: [security team, incident response, report security issue, security@1lookup.io]} gaps: - No /.well-known/security.txt (RFC 9116). - No published vulnerability-disclosure policy or safe-harbour statement. - No bug bounty or coordinated-disclosure program. - No PGP key or preferred-languages declaration. x-evidence: - url: https://www.1lookup.io/security http_status: 200 fetched: '2026-08-09'