generated: '2026-08-08' method: searched source: https://www.cadence.care/disclosure probe: true policy: - https://www.cadence.care/disclosure contact: - security@cadencerpm.com program: name: Cadence Responsible Disclosure Policy last_updated: '2025-10-01' bug_bounty: false platform: null safe_harbor: true acknowledgement_sla: seven business days triage_sla: ten business days for critical issues coordinated_disclosure: true scope: applies_to: https://cadence.care includes: related subdomains and services operated by Cadence out_of_scope: - denial of service (DoS/DDoS) attacks or availability-degrading tests - physical security testing - social engineering or phishing - high-volume automated scanning producing low-quality reports security_txt: published: false probed: - url: https://www.cadence.care/.well-known/security.txt status: 404 - url: https://cadencerpm.com/.well-known/security.txt status: 404 evidence: - source: https://www.cadence.care/disclosure kind: disclosure-page http_status: 200 fetched: '2026-08-08' keywords: - responsible disclosure - safe harbor - security@cadencerpm.com - coordinated disclosure notes: >- Cadence publishes a real, dated Responsible Disclosure Policy with a named security contact and explicit safe-harbor language, but does not serve an RFC 9116 /.well-known/security.txt — the machine-readable pointer researchers and scanners look for first is missing even though the human policy exists.