generated: '2026-09-05' method: searched probe: true probe_result: >- 0-working/probe-security-programs.py returned trust=none because it checks trust., security. and /trust|/security|/compliance, and 75F's page is at /software/security/. https://www.75f.io/security 301-redirects there and was fetched and read by hand (HTTP 200), which is why this file is method: searched rather than probed. url: https://www.75f.io/software/security/ certifications: - name: SOC 2 claim: >- "75F is proud to join the list of leading organizations that have achieved SOC 2 compliance." The page describes SOC 2 as the AICPA guidelines covering security, availability, processing integrity, confidentiality and privacy. report_available: false auditor_named: false - name: VAPT claim: >- 75F states it is "VAPT Certified" — vulnerability assessment and penetration testing, described as a rigorous process probing the system's security measures and resilience against breaches. report_available: false auditor_named: false frameworks: - name: O.R.A.N.G.E. Security Framework claim: >- 75F's own named set of protocols for securing building control systems, data, applications and networks. evidence: - source: https://www.75f.io/software/security/ http_status: 200 keywords: [soc 2, vapt, penetration] gaps: no_trust_portal: true no_subprocessor_list: true no_public_audit_report: true note: >- There is no trust.75f.io or security.75f.io host (both fail to resolve), no downloadable attestation, no named auditor and no subprocessor list. The claims are marketing-page assertions; a buyer's security team would have to request the SOC 2 report through sales. vulnerability_disclosure: found: false probed: - {url: 'https://www.75f.io/.well-known/security.txt', status: 404} - {url: 'https://75f.io/.well-known/security.txt', status: 301} - {url: 'https://api.75f.io/.well-known/security.txt', status: 404} - {url: 'https://www.75f.io/responsible-disclosure', status: 404} - {url: 'https://www.75f.io/security/responsible-disclosure', status: 404} - {url: 'https://www.75f.io/vulnerability-disclosure', status: 404} - {url: 'https://hackerone.com/75f', status: 404} - {url: 'https://bugcrowd.com/75f', status: 404} note: >- No security.txt, no responsible-disclosure page, no bug bounty program and no published security contact address. No security/75f-vulnerability-disclosure.yml is written and no `Security` pointer is emitted in apis.yml, because there is nothing to point at. For a vendor whose API physically actuates HVAC equipment in occupied commercial buildings, this is the single most consequential gap in the profile — a researcher who finds a flaw has no published route to report it.