generated: '2026-09-09' method: probed probe: true published: false policy: [] contact: [] note: 'No public vulnerability disclosure or bug bounty programme was found. Probed: /.well-known/security.txt on all eight known hosts (404 or 403, none served), hackerone.com/fenergo (404), bugcrowd.com/fenergo (404), fenergo.com/security (404), fenergo.com/responsible-disclosure (404), fenergo.com/vulnerability-disclosure (404), fenergo.com/trust-and-security/responsible-disclosure (404). No security@ address appears on the homepage, the Trust & Security page or the developer hub security pages. Fenergo does state it performs penetration and vulnerability testing as a service for client tenants, and routes security announcements through the Trust Center and client relationship managers — but that is an internal assurance programme, not an external reporting channel. No Security pointer is emitted for this provider because there is no published disclosure surface to point at. This is a real, closable gap.' evidence: - url: https://www.fenergo.com/.well-known/security.txt status: 404 - url: https://api.fenergox.com/.well-known/security.txt status: 403 - url: https://docs.fenergox.com/.well-known/security.txt status: 404 - url: https://identity.fenergox.com/.well-known/security.txt status: 404 - url: https://hackerone.com/fenergo status: 404 - url: https://bugcrowd.com/fenergo status: 404 - url: https://www.fenergo.com/security status: 404 - url: https://www.fenergo.com/responsible-disclosure status: 404