generated: '2026-08-17' method: searched probe: true source: https://elium.com/trust/controls policy: [] policy_published: false contact: [security@elium.com] contact_url: https://elium.com/trust/controls bug_bounty: null finding: >- Elium publishes a security contact and a public security-controls page, but NO responsible-disclosure policy and NO bug-bounty programme. security@elium.com is presented as a general security-team mailbox ("handles vendor reviews, RFPs, audits, and architecture questions"), not as a vulnerability intake with scope, safe-harbour terms, or response targets. A researcher has an address to write to and nothing that tells them the rules. Recorded honestly: a reachable channel, an absent programme. what_exists: - {item: security contact, value: 'security@elium.com', source: 'https://elium.com/trust'} - {item: public security-controls page, value: 'https://elium.com/trust/controls'} - item: third-party penetration testing value: >- "Penetration tests are conducted regularly by independent third parties and vulnerability scans are automated. Findings are assessed and remediated per defined SLAs." source: https://elium.com/trust/controls - item: penetration-test reports value: 2025 and 2024 reports listed as documents available on request source: https://elium.com/trust - item: incident-response programme with acknowledgement/resolution SLAs source: https://elium.com/trust/controls what_is_missing: - No /.well-known/security.txt (RFC 9116) on elium.com or api.elium.com - both 404. - No responsible-disclosure or vulnerability-disclosure page - /security and /responsible-disclosure both 404. - No HackerOne, Bugcrowd, Intigriti, YesWeHack or self-hosted bounty programme found. - No stated scope, safe harbour, PGP key, or researcher response-time commitment. false_positive_rejected: url: https://help.elium.com/.well-known/security.txt http_status: 200 content_type: text/plain verdict: rejected reason: >- This is INTERCOM's security.txt, served because Elium's help centre is Intercom-hosted. Its own Canonical field is https://app.intercom.com/.well-known/security.txt and its contacts are bugcrowd.com/intercom and security@intercom.com. Crediting it to Elium would attribute another company's bug-bounty programme to them, so it is deliberately not saved and no SecurityTxt pointer is wired. evidence: - {source: 'https://elium.com/trust', http_status: 200, kind: security-contact, probed: '2026-08-17'} - {source: 'https://elium.com/trust/controls', http_status: 200, kind: security-policy-page, probed: '2026-08-17'} - {source: 'https://elium.com/.well-known/security.txt', http_status: 404, kind: absent, probed: '2026-08-17'} - {source: 'https://api.elium.com/.well-known/security.txt', http_status: 404, kind: absent, probed: '2026-08-17'} - {source: 'https://elium.com/security', http_status: 404, kind: absent, probed: '2026-08-17'} - {source: 'https://elium.com/responsible-disclosure', http_status: 404, kind: absent, probed: '2026-08-17'} recommendation: >- Publishing /.well-known/security.txt on elium.com pointing at security@elium.com and a short disclosure page would cost Elium almost nothing and is the single cheapest security-transparency gap on this profile.