generated: '2026-07-18' method: searched probe: true source: https://www.getbenepass.com/.well-known/security.txt policy: - https://trust.getbenepass.com/ contact: - mailto:security@getbenepass.com - mailto:security+trustcenter@getbenepass.com encryption: https://keys.openpgp.org/vks/v1/by-fingerprint/A821B964FFCB61042A4F57720B85488DD2A55BDE evidence: - source: https://www.getbenepass.com/.well-known/security.txt kind: security.txt (RFC 9116, live probe) - source: https://trust.getbenepass.com/ kind: responsible-disclosure (SafeBase trust portal — "If you think you may have discovered a vulnerability, please send us a note") notes: >- Benepass publishes an RFC 9116 security.txt with a security@ contact and PGP encryption key. A responsible-disclosure channel is surfaced on the SafeBase trust portal (security+trustcenter@getbenepass.com). No public bug-bounty program (HackerOne/Bugcrowd/Intigriti) was found. The security.txt Expires date (2026-06-16) is in the past as of this pass.