generated: '2026-09-05' method: searched source: https://7learnings.com/security-compliance-data-protection/ summary: >- 7Learnings publishes a dedicated security page and a named security contact address, but no formal vulnerability disclosure policy. Be precise about the difference when reading this: there is somewhere to send a report, and nothing published about what happens next. security_contact: present: true email: security@7learnings.com published_on: - https://7learnings.com/security-compliance-data-protection/ - https://7learnings.com/developer/ status: 200 security_page: present: true url: https://7learnings.com/security-compliance-data-protection/ status: 200 localized: https://7learnings.com/de/sicherheit-compliance-datenschutz/ disclosure_policy: present: false detail: >- No responsible-disclosure or vulnerability-disclosure policy page was found. Probed /security/ (404), /responsible-disclosure/ (not in sitemap), /vulnerability-disclosure/ (not in sitemap). The 96-page public sitemap contains no disclosure policy page. No safe harbour statement, no scope definition, and no response-time commitment are published. security_txt: present: false path: /.well-known/security.txt status: 404 note: >- RFC 9116 would make the existing contact machine-discoverable at essentially zero cost - the address (security@7learnings.com) already exists and is already public. bug_bounty: present: false programs_checked: [HackerOne, Bugcrowd, Intigriti] detail: No public bug bounty or coordinated disclosure program was found. related_program: penetration_testing: Annual penetration tests of SaaS and Cloud services vulnerability_scanning: Daily scans of dependencies and container images evidence: https://7learnings.com/security-compliance-data-protection/ evidence: - {url: 'https://7learnings.com/security-compliance-data-protection/', status: 200} - {url: 'https://7learnings.com/.well-known/security.txt', status: 404} - {url: 'https://7learnings.com/security/', status: 404}