generated: '2026-07-18' method: searched probe: true contact: - mailto:security@cuvva.com policy: [] evidence: - source: DNS CAA record for cuvva.com kind: iodef-contact detail: 'CAA 0 iodef "mailto:security@cuvva.com" — a currently-published security/incident reporting contact.' - source: https://firebounty.com/52-cuvva/ kind: historical-bug-bounty detail: >- Cuvva previously ran a HackerOne vulnerability disclosure program (hackerone.com/cuvva, listed 2017-05-22 to 2019-08-06) scoping the apps, api.prod.cuv-prod.app, www.cuvva.com and *.cuv-prod.app. The HackerOne page now returns 404, so the program appears inactive; the DNS iodef contact remains the live disclosure channel. notes: >- No /.well-known/security.txt is served (404 on cuvva.com and api hosts). The live security contact is published via the domain CAA iodef record.