generated: '2026-09-05' method: searched probe: true probe_note: >- 0-working/probe-security-programs.py returned vdp=none: there is no /.well-known/security.txt on any 1Token host (all 404) and no /security, /responsible-disclosure or /vulnerability-disclosure page. The channel below was found by reading the site footer instead. policy: [] policy_url: null bug_bounty: null contact: - security@1token.trade contact_label: Security Report detail: >- 1Token publishes a dedicated security-reporting mailbox as a "Security Report" link in the global site footer, alongside separate mailboxes for legal inquiries and service. That is a real, first-party intake channel for vulnerability reports. What it is NOT is a disclosure policy: there is no published scope, safe-harbour statement, response-time commitment, bug bounty, or RFC 9116 security.txt. The cheapest improvement available to 1Token here is to serve /.well-known/security.txt naming this same address. evidence: - source: https://blog.1token.tech/ http_status: 200 kind: footer-link detail: 'Security Report in the server-rendered site footer' - source: https://1token.tech/.well-known/security.txt http_status: 404 kind: negative - source: https://1token.tech/security http_status: 404 kind: negative domain_note: >- The mailbox is on 1token.trade, 1Token's original domain, which redirects to 1token.tech (https://1token.trade/swagger -> https://1token.tech/swagger). Same company, legacy mail domain. checked: '2026-09-05'