generated: '2026-08-04' method: searched probe: true policy: - https://trustcenter.controlup.com/ contact: - security@controlup.com program: type: responsible-disclosure intake: >- A "Report issue" action on the SafeBase-hosted trust center opens a report addressed to security@controlup.com with a "SafeBase Responsible Disclosure Report for ControlUp" subject line. bug_bounty: false platform: null safe_harbour_published: false response_sla_published: false security_txt: published: false hosts_probed: - https://www.controlup.com/.well-known/security.txt - https://api.controlup.com/.well-known/security.txt - https://api.controlup.io/.well-known/security.txt - https://support.controlup.com/.well-known/security.txt result: 404 on every host evidence: - {source: https://trustcenter.controlup.com/, fetched: '2026-08-04', kind: trust-center, found: [security@controlup.com, responsible disclosure report intake]} - {source: https://www.controlup.com/security/, fetched: '2026-08-04', http_status: 200, kind: page, found: [], note: 'Product marketing page for ControlUp''s patch-and-vulnerability-management capability, not a disclosure policy. Recorded so a later run does not re-read it as one.'} gaps: - No RFC 9116 security.txt on any ControlUp host. - No published safe-harbour statement, scope definition, or acknowledgement/response timeline. - No public bug bounty (no HackerOne, Bugcrowd or Intigriti program found). - >- The disclosure channel is reachable only by rendering a JavaScript trust-center portal that returns 403 to non-browser clients — a researcher using ordinary tooling would not discover it.