generated: '2026-08-01' method: searched probe: true source: https://www.dailypay.com/security/vulnerability-disclosure-program/ url: https://www.dailypay.com/security/vulnerability-disclosure-program/ program_name: DailyPay Vulnerability Disclosure Program policy: - https://www.dailypay.com/security/vulnerability-disclosure-program/ contact: [] intake: mechanism: web form form_url: https://www.dailypay.com/security/vulnerability-disclosure-program/ email: not published note: >- Reports are submitted through a form on the program page. DailyPay publishes no security@ address and serves no /.well-known/security.txt on any host, so the form is the only documented intake channel. bug_bounty: present: false platform: none note: No HackerOne, Bugcrowd or Intigriti program was found. scope: definition: >- "an unintentional flaw in our product that could give an intruder a way to compromise its integrity, availability, or confidentiality" safe_harbor: published: false note: >- The page thanks researchers for responsible disclosure but contains no explicit safe-harbor or legal-protection clause. response_commitment: sla: not published statement: >- "Our dedicated Security team will thoroughly investigate your report and reach out to you at the earliest opportunity." evidence: - source: https://www.dailypay.com/security/vulnerability-disclosure-program/ kind: disclosure-page http_status: 200 fetched: '2026-08-01' - source: https://www.dailypay.com/security/ kind: security-page-link http_status: 200 fetched: '2026-08-01' - source: https://www.dailypay.com/.well-known/security.txt kind: security.txt http_status: 404 fetched: '2026-08-01' result: absent gaps: - No RFC 9116 /.well-known/security.txt on any DailyPay host. - No published security contact email address. - No safe-harbor language and no response-time commitment.