generated: '2026-09-07' method: probed probe: true source: well-known/cambio-uruguay-security.txt + live probes of the URLs it names, 2026-09-07 summary: >- A vulnerability-disclosure channel exists — a served RFC 9116 security.txt with a working mailto contact — but the program pages it advertises are dead: both the Policy and Acknowledgments URLs return 404, and the file's Expires date (2026-06-09) had already passed when probed on 2026-09-07. The disclosure CONTACT is real; the disclosure POLICY is currently a broken claim. No bug bounty program was found on HackerOne, Bugcrowd, or Intigriti, and no trust center or compliance certifications are published. contact: - mailto:admin@cambio-uruguay.com - https://cambio-uruguay.com policy: - url: https://cambio-uruguay.com/security-policy status: 404 note: advertised in security.txt but not served acknowledgments: - url: https://cambio-uruguay.com/security-acknowledgments status: 404 note: advertised in security.txt but not served security_txt: url: https://cambio-uruguay.com/.well-known/security.txt status: 200 expires: '2026-06-09' expired_at_probe: true bug_bounty: null trust_center: null evidence: - url: https://cambio-uruguay.com/.well-known/security.txt status: 200 - url: https://cambio-uruguay.com/security-policy status: 404 - url: https://cambio-uruguay.com/security-acknowledgments status: 404