generated: '2026-09-02' method: searched probe: true source: >- https://www.cadasto.com/.well-known/security.txt (HTTP 200, text/plain, fetched 2026-09-02 — saved verbatim to well-known/cadasto-security.txt) and the identical document served at https://cadasto.io/.well-known/security.txt (HTTP 200). Corroborated by SECURITY.md files in the first-party GitHub repositories github.com/Cadasto/openehr-server-mcp, /openehr-sdk-go, /openehr-bmm and /openehr-assistant-plugin. description: >- Cadasto publishes a minimal but real RFC 9116 security.txt with a working contact address and a valid, non-expired Expires field. It does NOT publish a disclosure policy page, a safe harbour statement, a scope definition, a response SLA, or a bug bounty. contact: - mailto:security@cadasto.com expires: '2026-12-31T11:00:00.000Z' expired: false fields_present: [Contact, Expires] fields_absent: [Policy, Encryption, Acknowledgments, Preferred-Languages, Canonical, Hiring, CSAF] hosts_serving: - https://www.cadasto.com/.well-known/security.txt - https://cadasto.io/.well-known/security.txt bug_bounty: program: null platform: null evidence: >- No HackerOne, Bugcrowd or Intigriti program was found for cadasto.com or cadasto.io, and security.txt names no policy URL. disclosure_policy_url: null safe_harbour: false repository_policy: present: true files: - https://github.com/Cadasto/openehr-sdk-go/blob/main/SECURITY.md - https://github.com/Cadasto/openehr-server-mcp/blob/main/SECURITY.md - https://github.com/Cadasto/openehr-bmm/blob/main/SECURITY.md - https://github.com/Cadasto/openehr-assistant-plugin/blob/main/SECURITY.md evidence: - source: well-known/cadasto-security.txt kind: RFC 9116 security.txt served at 200 on two hosts fetched: '2026-09-02' gaps: - security.txt carries no Policy field, so a researcher has a contact address but no published scope, no disclosure timeline and no safe-harbour commitment. - Expires is 2026-12-31; the document will go stale in under four months.