generated: '2026-09-09' method: searched probe: true source: https://advicepay.com/security/ policy: - https://advicepay.com/security/ contact: - support@advicepay.com security_txt: false bug_bounty: program: false platform: null note: No HackerOne, Bugcrowd or Intigriti program was found, and none is referenced on the security page. statement: >- "To report a security bug or vulnerability, please email support@advicepay.com" — published under "More information" on the AdvicePay security page. assessment: >- A real but minimal vulnerability-reporting route: a named channel on a public page, with no dedicated security@ alias, no published safe-harbour or disclosure policy, no stated response or remediation timeline, and no /.well-known/security.txt (probed on all five hosts in this record on 2026-09-09 — every one 404s, see well-known/advicepay-well-known.yml). Reports go to the same general support inbox customers use for billing questions. The provider-fixable gap here is small and specific: publishing an RFC 9116 security.txt pointing at this page, and a short disclosure policy, would cost little and close it. related_controls: penetration_testing: performed: true cadence: annual party: independent third party source: https://advicepay.com/security/ evidence: - source: https://advicepay.com/security/ status: 200 kind: security-page keywords: - report a security bug or vulnerability - penetration tests