generated: '2026-08-12' method: searched probe: true source: https://enboarder.com/legal/vulnerability/ policy: - https://enboarder.com/legal/vulnerability/ contact: - security@enboarder.com bug_bounty: false bug_bounty_platform: null safe_harbor: true scope: in_scope: - '*.enboarder.com' out_of_scope_note: >- "Any service not expressly listed above, such as any connected services, is excluded from scope and is not authorised for testing." safe_harbor_text: >- "If you make a good faith effort to comply with this policy during your security research: We will consider your research to be authorised and will work with you to understand and resolve the issue quickly. Enboarder will not recommend or pursue legal action related to your research." security_txt: served: false detail: >- https://enboarder.com/.well-known/security.txt returns 404 (probed 2026-08-12). The policy exists as an HTML page only, so an automated RFC 9116 lookup will not find it. Publishing a security.txt pointing at /legal/vulnerability/ and security@enboarder.com would make this discoverable. evidence: - source: https://enboarder.com/legal/vulnerability/ kind: disclosure page http_status: 200 keywords: - vulnerability disclosure - good faith - authorised - security@enboarder.com - source: https://enboarder.com/.well-known/security.txt kind: security.txt http_status: 404