generated: '2026-08-04' method: searched probe: true probe_result: none grade: contact-only summary: | ExecOnline publishes a security contact email but NO vulnerability-disclosure program: no security.txt of its own, no responsible-disclosure or safe-harbour policy page, and no bug-bounty program on HackerOne, Bugcrowd, or Intigriti. Because there is no published disclosure POLICY, this repo deliberately does NOT carry a `Security` / `SecurityPolicy` pointer in apis.yml — the operational security_disclosure check reads that type, and awarding it for a bare mailto would overstate the posture. policy: [] contact: - mailto:security@execonline.com - mailto:privacy@execonline.com bug_bounty: none security_txt: none evidence: - source: https://www.execonline.com/privacy-policy/ kind: privacy-policy detail: Publishes security@execonline.com as the security-incident contact and privacy@execonline.com as the Data Protection Officer / privacy contact. - source: probe-security-programs.py kind: automated-probe detail: 'vdp=none — /.well-known/security.txt, /security, /security/responsible-disclosure, /responsible-disclosure and /vulnerability-disclosure all missed on execonline.com.' not_ours: - url: https://status.execonline.com/.well-known/security.txt owner: Atlassian note: Vendor document (Canonical https://www.atlassian.com/.well-known/security.txt). - url: https://support.execonline.com/.well-known/security.txt owner: Intercom note: Vendor document (Canonical https://app.intercom.com/.well-known/security.txt); Bugcrowd program belongs to Intercom. x-evidence: fetched: '2026-08-04' http_status: 200