generated: '2026-08-12' method: searched probe: true source: https://app.ev.energy/.well-known/security.txt security_txt: url: https://app.ev.energy/.well-known/security.txt status: 200 file: well-known/ev-energy-security.txt spec: RFC 9116 fields: Contact: mailto:security@ev.energy Expires: '2030-01-01T00:00:00.000Z' Preferred-Languages: en Policy: https://ev.energy/vulnerability-disclosure-policy/ Hiring: https://ev.energy/careers/ contact: - mailto:security@ev.energy policy: - url: https://ev.energy/vulnerability-disclosure-policy/ reachable: false final_status: 200 final_url: https://www.ev.energy/privacy note: 'DEFECT worth reporting to the provider: the Policy URL published in security.txt does not resolve to a vulnerability-disclosure policy. It 301-chains ev.energy -> www.ev.energy -> https://www.ev.energy/privacy, the general privacy notice. The disclosure contact address is real; the policy document behind it is not published.' bug_bounty: published: false note: No HackerOne, Bugcrowd or Intigriti programme found for ev.energy. evidence: - url: https://app.ev.energy/.well-known/security.txt status: 200 - url: https://ev.energy/vulnerability-disclosure-policy/ status: 301 - url: https://www.ev.energy/privacy status: 200 - url: https://www.ev.energy/.well-known/security.txt status: 404 checked: '2026-08-12'