generated: '2026-09-02' method: searched probe: true source: https://assetplanner.com/.well-known/security.txt note: >- Ameresco publishes no security.txt, /security or /responsible-disclosure page on www.ameresco.com (all probed 2026-09-02, 404). Its AssetPlanner platform host does serve an RFC 9116 security.txt naming a reporting mailbox. AssetPlanner is Ameresco's own product — the login page footers "Ameresco 2026" and links to https://www.ameresco.com/asset-planning-software-solutions/ — so this is Ameresco's disclosure surface, not a third party's. policy: [] contact: - security@assetplanner.com canonical: https://assetplanner.com/.well-known/security.txt preferred_languages: en bug_bounty: null evidence: - source: https://assetplanner.com/.well-known/security.txt kind: security.txt status: 200 file: well-known/ameresco-assetplanner-security.txt - source: https://www.ameresco.com/.well-known/security.txt kind: security.txt status: 404 gaps: - 'No Policy field: the security.txt names a contact but links no disclosure policy, so a researcher has no published scope, safe-harbour statement or SLA.' - 'No Expires field, which RFC 9116 requires.' - 'No security.txt on the corporate domain www.ameresco.com.' maintainers: - FN: Kin Lane email: kin@apievangelist.com