generated: '2026-07-18' method: searched probe: true source: https://reflag.com/security + https://reflag.com/legal/security-policy policy: - https://reflag.com/legal/security-policy contact: - hello@reflag.com bug_bounty: null security_txt: null note: >- Reflag publishes a security policy page and a security contact (hello@reflag.com), and describes encryption in transit/at rest, regular penetration testing, and a Data Processing Agreement. No /.well-known/security.txt (RFC 9116) and no public bug-bounty program (HackerOne/Bugcrowd/Intigriti) were found. evidence: - { source: https://reflag.com/legal/security-policy, kind: security-policy } - { source: https://reflag.com/security, kind: security-overview }