generated: '2026-09-05' method: probed source: >- /.well-known/security.txt probed on ten Cledara hosts (see well-known/cledara-well-known.yml), plus https://www.cledara.com/security and https://trust.cledara.com/ provider: Cledara providerId: cledara present: false security_txt: served: false hosts_probed: - www.cledara.com - cledara.com - api.cledara.com - api-docs.cledara.com - app.cledara.com - help.cledara.com - announcements.cledara.com - data.cledara.com - statuspage.cledara.com - trust.cledara.com note: >- 404 on every host except statuspage.cledara.com and trust.cledara.com, which return a single-page-app HTML shell with a 200 for every path — not a security.txt. disclosure_policy: published: false url: null bug_bounty: program: null platform: null note: No HackerOne, Bugcrowd or Intigriti program was found for Cledara. security_contact: published: false note: >- Cledara's security page describes penetration testing and tokenization but names no security contact address, no responsible-disclosure policy and no PGP key. The only published route for a reporter is the general help centre. finding: >- HONEST ABSENCE. Cledara is an FCA-registered EMD agent issuing Mastercard and Visa cards and holds SOC 2 Type II, yet publishes no coordinated vulnerability disclosure route at all. This is a gap the provider can close cheaply with an RFC 9116 security.txt at https://www.cledara.com/.well-known/security.txt. maintainers: - FN: Kin Lane email: kinlane@gmail.com