generated: '2026-09-12' method: searched source: https://www.itrsgroup.com/about/security-center specification: API Commons VulnerabilityDisclosure specificationVersion: '0.1' provider: Geneos providerId: geneos disclosure: published: true grade: partial channel: support-ticket url: https://support.itrsgroup.com/requests/new policy_url: https://www.itrsgroup.com/about/security-center http_status: 200 probed: '2026-09-12' quote: >- "If you've noticed any abuse, misuse, exploitation, or experienced an incident with your account data or security, open a support ticket and we'll be ready to help." note: >- This is a stated route for reporting a security problem to ITRS Group, and it is why a `Security` pointer is wired in apis.yml. It is NOT a formal vulnerability disclosure policy: there is no safe-harbour statement, no scope definition, no acknowledgement or remediation timeline, no PGP key, no dedicated security@ address, and the route is a general support queue that a non-customer may not be able to open a ticket in. Graded `partial` rather than `published` so the difference stays visible. security_txt: published: false probed: - url: https://www.itrsgroup.com/.well-known/security.txt status: 404 - url: https://itrsgroup.com/.well-known/security.txt status: 404 - url: https://docs.itrsgroup.com/.well-known/security.txt status: 404 - url: https://community.itrsgroup.com/.well-known/security.txt status: 404 note: >- No RFC 9116 security.txt on any host. No `SecurityTxt` pointer is wired. bug_bounty: program: false searched: - HackerOne - Bugcrowd - Intigriti note: No public bug bounty or coordinated disclosure programme found. cve_history: advisory_page: not found note: >- No public security advisory feed, RSS, or GitHub Security Advisories surface was found for Geneos. Patches are announced inside the versioned release notes at https://docs.itrsgroup.com/docs/all/geneos/7x-geneos-release-notes/index.html recommendation_to_provider: >- Publishing /.well-known/security.txt on www.itrsgroup.com with a Contact and a Policy line would take minutes and would close the single most mechanical gap in this profile. A named security@ alias and a short safe-harbour statement would move this from `partial` to a real disclosure policy.