generated: '2026-08-06' method: searched probe: true source: https://trust.altr.com/ policy: - https://trust.altr.com/ contact: - compliance@altr.com security_txt: false bug_bounty: null programs: [] controls_published: - Responsible Disclosure - Vulnerability & Patch Management - Penetration Testing - Incident Response Policy - Code Analysis reports_available_on_request: - SOC 2 Report - PCI DSS Report - HIPAA Report - Pentest Report - Vulnerability Assessment Report - Network Diagram evidence: - source: https://trust.altr.com/ http_status: 200 kind: trust-center found: - Responsible Disclosure - Vulnerability & Patch Management - compliance@altr.com - source: https://altr.com/.well-known/security.txt http_status: 404 kind: security.txt - source: https://altr.com/security/ http_status: 404 kind: disclosure-page notes: - ALTR names a Responsible Disclosure control on its public SafeBase-hosted trust center, but the policy document itself sits behind the trust center's request/NDA flow rather than on a public URL. - No RFC 9116 /.well-known/security.txt is published on any ALTR host, and no public bug bounty program (HackerOne / Bugcrowd / Intigriti) was found. - Publishing a security.txt and a public responsible-disclosure page would close the gap — this is a provider-side fix, not a limitation of the probe.