generated: '2026-08-09' method: probed probe: true result: none finding: >- Cerby publishes NO vulnerability disclosure channel that a researcher could find and use. This is a recorded negative, not an unchecked box. policy: [] contact: [] bug_bounty: none probes: - url: https://www.cerby.com/.well-known/security.txt http_status: 404 - url: https://cerby.com/.well-known/security.txt http_status: 404 - url: https://api.cerby.com/.well-known/security.txt http_status: 404 - url: https://app.cerby.com/.well-known/security.txt http_status: 404 - url: https://docs.cerby.com/.well-known/security.txt http_status: 404 - url: https://developer.cerby.com/.well-known/security.txt http_status: 404 - url: https://help.cerby.com/.well-known/security.txt http_status: 404 - url: https://www.cerby.com/security http_status: 200 outcome: >- A Security Policy (contractual security addendum) with no reporting channel. Searched the body for "security@", "responsible disclosure", "bug bounty", "HackerOne", "Bugcrowd" — none present. - url: https://trust.cerby.com/ http_status: 403 outcome: Cloudflare bot challenge; a disclosure policy may be published behind it but could not be read. searched: bug_bounty_platforms: [HackerOne, Bugcrowd, Intigriti] result: no public Cerby program found gap: >- An identity and credential-management vendor — a company whose product holds its customers' passwords, TOTP seeds, and vault material — publishes no security.txt and no public route for reporting a vulnerability. The Security Policy commits to remediating critical and high vulnerabilities within 30 days, but does not say how anyone outside the company is supposed to report one. An RFC 9116 security.txt at https://www.cerby.com/.well-known/security.txt with a Contact: and Policy: field is the lowest-cost fix available to them. x-evidence: - url: https://www.cerby.com/.well-known/security.txt http_status: 404 fetched: '2026-08-09' - url: https://www.cerby.com/security http_status: 200 fetched: '2026-08-09'