generated: '2026-08-17' method: searched probe: true source: >- https://cybelangel.com/security.txt (HTTP 200, harvested verbatim to well-known/cybelangel-security.txt), plus negative probes of the canonical disclosure locations listed in evidence[] policy: [] contact: - security@beapi.fr bug_bounty: program: null platform: null note: >- No bug bounty. hackerone.com/cybelangel and bugcrowd.com/cybelangel both return 404, and no Intigriti/YesWeHack program was found. grade: non-conformant finding: >- CybelAngel — an external attack surface management vendor whose entire product is telling other companies about their exposures — publishes a security-contact file that is broken in three ways at once, and it is worth stating plainly because this is the one provider category where a reader will look: 1. WRONG PATH. The file is served at https://cybelangel.com/security.txt, the pre-RFC-9116 root location. The canonical /.well-known/security.txt returns 404 on cybelangel.com, api.cybelangel.com, auth.cybelangel.com and developers.cybelangel.com. A scanner that follows RFC 9116 finds nothing. 2. THIRD-PARTY CONTACT. The only Contact: is security@beapi.fr. BeAPI is the WordPress agency that operates the marketing site, not CybelAngel. A researcher who follows the file reports a CybelAngel vulnerability to CybelAngel's web contractor. There is no security@cybelangel.com or PSIRT address published anywhere. 3. NOT A CONFORMANT DOCUMENT. Two lines, no Expires: field (a MUST in RFC 9116), no Policy:, no Encryption:, no Preferred-Languages:, no Canonical:. The published contact for anything security-related is the generic support address (support@cybelangel.com, from the docs) or the website contact form. evidence: - {source: 'https://cybelangel.com/security.txt', status: 200, content_type: 'text/plain', kind: security.txt, file: well-known/cybelangel-security.txt} - {source: 'https://cybelangel.com/.well-known/security.txt', status: 404, kind: negative-probe} - {source: 'https://api.cybelangel.com/.well-known/security.txt', status: 404, kind: negative-probe} - {source: 'https://auth.cybelangel.com/.well-known/security.txt', status: 404, kind: negative-probe} - {source: 'https://developers.cybelangel.com/.well-known/security.txt', status: 404, kind: negative-probe} - {source: 'https://cybelangel.com/security/', status: 404, kind: negative-probe} - {source: 'https://cybelangel.com/responsible-disclosure/', status: 404, kind: negative-probe} - {source: 'https://cybelangel.com/vulnerability-disclosure/', status: 404, kind: negative-probe} - {source: 'https://cybelangel.com/trust/', status: 404, kind: negative-probe} - {source: 'https://trust.cybelangel.com/', status: 000, kind: negative-probe, note: 'DNS does not resolve'} - {source: 'https://hackerone.com/cybelangel', status: 404, kind: negative-probe} - {source: 'https://bugcrowd.com/cybelangel', status: 404, kind: negative-probe} related_security_posture: note: >- Absence of a disclosure program is not absence of a security program. CybelAngel holds ISO/IEC 27001:2022 (A-LIGN, early 2026) and SOC 2 Type I (A-LIGN Assurance, signed off 2026-01-31, renewed), and publishes practice detail — AES at rest, TLS in transit, daily vulnerability scanning, monthly role-based access review, token-based 2FA via Google Workspace. See conformance/cybelangel-conformance.yml. pages: - https://cybelangel.com/solutions/compliance-cybelangel/ - https://cybelangel.com/blog/cybelangel-achieves-iso-27001-certification/ - https://cybelangel.com/blog/cybelangel-soc-2-type-1-certification-2026/