generated: '2026-08-12' method: searched source: https://www.fevo.com/security program: contact-only policy_url: null policy_published: false disclosure_page: https://www.fevo.com/security contact: security_questions@fevo.com contact_type: email note: >- FEVO accepts vulnerability reports, but only as a sentence at the bottom of its security page: "If you have any questions, comments or concerns or if you wish to report a potential security issue, please contact security_questions@fevo.com." That is a real, named, monitored channel and it is recorded as such. Everything a coordinated disclosure policy would specify is absent: no scope, no safe-harbour language, no acknowledgement or remediation timelines, no severity/triage process, no PGP key, no preference for encrypted reports, and no credit or reward. The same address handles general security questionnaires, so a report competes with sales-cycle traffic. bug_bounty: present: false platform: null probed: - platform: HackerOne result: no program found - platform: Bugcrowd result: no program found - platform: Intigriti result: no program found security_txt: present: false probed: - url: https://www.fevo.com/.well-known/security.txt status: 404 - url: https://www.gofevo.com/.well-known/security.txt status: 404 - url: https://report.gofevo.com/.well-known/security.txt status: 404 - url: https://fevo-enterprise.com/.well-known/security.txt status: 404 note: >- No RFC 9116 security.txt on any FEVO host. The contact exists but is not machine discoverable — a scanner or agent has no way to find it without parsing a marketing page. related_controls: vulnerability_scanning: 'published: "We perform vulnerability scanning and actively monitor for threats."' penetration_testing: 'published: independent third-party penetration test at least annually' incident_response: 'published: process with escalation, rapid mitigation and communication' see: security/fevo-trust-center.yml x-evidence: - fetched: '2026-08-12' url: https://www.fevo.com/security http_status: 200 - fetched: '2026-08-12' url: https://www.fevo.com/.well-known/security.txt http_status: 404