generated: '2026-08-13' method: probed source: >- /.well-known/security.txt probes across every backstitch host, plus a search of backstitch.io and the public bug-bounty platforms program_found: false security_txt: served: false probes: - {url: 'https://api.backstit.ch/.well-known/security.txt', status: 404} - {url: 'https://docs.backstit.ch/.well-known/security.txt', status: 404} - {url: 'https://www.backstitch.io/.well-known/security.txt', status: 404} - {url: 'https://backstitch.io/.well-known/security.txt', status: 404} - url: https://trust.backstitch.io/.well-known/security.txt status: 200 accepted: false note: >- REJECTED as a false positive. trust.backstitch.io is a Vanta single-page app whose catch-all returns 200 with the same HTML shell for every path; the body is ``, not an RFC 9116 document. disclosure_page: url: null note: >- No /security, /security-policy, /vulnerability-disclosure or responsible- disclosure page was found on backstitch.io (https://www.backstitch.io/security -> 404). The site's only security destination is the Vanta trust center at https://trust.backstitch.io/, whose content is JS-rendered and whose data API is auth-gated, so no disclosure policy or security contact could be read anonymously. bug_bounty: platform: null url: null note: No HackerOne, Bugcrowd or Intigriti program was found for backstitch. contacts: [] note: >- No published vulnerability disclosure program was found. No `Security` pointer is emitted — an absence recorded is not a presence, and the `security_disclosure` check must not fire on this file. checked: '2026-08-13'