generated: '2026-09-05' method: probed source: Probes of /.well-known/security.txt and /security.txt on twelve Dealogic and ION hosts, plus a search of dealogic.com's complete page sitemap and https://dealogic.com/security/. published: false detail: Dealogic operates no vulnerability disclosure programme that a researcher can find. No security.txt is served on any host (all 404, see well-known/dealogic-well-known.yml); there is no /security/disclosure, /responsible-disclosure or /vulnerability page in the dealogic.com sitemap; there is no HackerOne, Bugcrowd or Intigriti listing. https://dealogic.com/security/ offers an Information Security team contact for questions about security practices, which is a sales-and-audit channel, not a disclosure policy - it states no scope, no safe harbour and no response commitment. policy_url: null contact: null bug_bounty: null safe_harbour: false probes: - url: https://dealogic.com/.well-known/security.txt status: 404 - url: https://dealogic.com/security.txt status: 404 - url: https://www.dealogic.com/.well-known/security.txt status: 404 - url: https://login.dealogic.com/.well-known/security.txt status: 404 - url: https://spac.analytics.dealogic.com/.well-known/security.txt status: 401 - url: https://iongroup.com/.well-known/security.txt status: 404 pointer_note: No `Security` pointer is wired into apis.yml. The pointer asserts the provider publishes a disclosure programme, and this probe records that they do not.