generated: '2026-08-04' method: probed probe: true found: false source: live probes on 2026-08-04 summary: >- NEGATIVE RESULT, recorded so the search is not repeated. Copper publishes no vulnerability disclosure programme that could be found from the public surface: no RFC 9116 security.txt on any host, no responsible-disclosure or vulnerability-disclosure page, no bug bounty programme on HackerOne, Bugcrowd or Intigriti, and no security@ reporting address. The /en/security page describes security posture and certifications but contains no reporting channel for external researchers. Because nothing was verified, NO `Security` or `VulnerabilityDisclosure` pointer is wired into apis.yml — this file documents the absence only. policy: [] contact: [] bug_bounty: hackerone: false bugcrowd: false intigriti: false self_hosted: false security_txt: published: false hosts_checked: - copper.co - www.copper.co - api.copper.co - developer.copper.co note: >- www.copper.co returns 200 for /.well-known/security.txt but the body is the marketing SPA HTML shell, not a security.txt — rejected as a catch-all false positive. pages_checked: - url: https://copper.co/en/security status: 200 disclosure_program_found: false note: Security posture and certifications only; no reporting channel or disclosure policy. - url: https://copper.co/security status: 200 note: Redirects to /en/security. probe_output: 'probe-security-programs.py copper-co -> vdp=none' related: trust_center: security/copper-co-trust-center.yml contact_general: hello@copper.co recommendation: >- Publishing /.well-known/security.txt with a Policy and Contact, and a responsible disclosure page, is the cheapest operational-transparency win available to Copper — and a conspicuous gap for a custodian holding institutional digital assets.