generated: '2026-09-19' method: searched probe: true source: https://signals.gitdealflow.com/.well-known/security.txt (primary — carries Policy), https://gitdealflow.com/.well-known/security.txt, https://github.com/kindrat86/mcp-deal-flow-signal/blob/main/SECURITY.md contact: - mailto:signals@gitdealflow.com policy: https://signals.gitdealflow.com/about preferred_languages: [en] expires: 2027-09-19 on the signals host (regenerated per request); 2027-07-20 on the apex canonical: - https://signals.gitdealflow.com/.well-known/security.txt - https://gitdealflow.com/.well-known/security.txt acknowledgement: We aim to acknowledge within 72 hours (security.txt comment, verbatim) reporting_rules: 'Report by email; do not file public GitHub issues for security findings' scope_statement: 'This service exposes a public, no-auth read-only API. There is no user authentication, no session storage, and no sensitive PII. Findings of interest are typically: SSRF in image proxies, prototype pollution in our build pipeline, or social-engineering vectors via our public APIs.' bug_bounty: program: none platforms_checked: [HackerOne, Bugcrowd, Intigriti] note: no paid programme found; disclosure is email-based repository_policy: SECURITY.md present in github.com/kindrat86/mcp-deal-flow-signal (not fetched) evidence: - source: https://signals.gitdealflow.com/.well-known/security.txt kind: security.txt (live probe, 200, 732 bytes, Contact + Expires + Preferred-Languages + Canonical + Policy) - source: https://gitdealflow.com/.well-known/security.txt kind: security.txt (live probe, 200, 154 bytes, Contact + Expires + Preferred-Languages + Canonical) files: - well-known/gitdealflow-com-signals-security.txt - well-known/gitdealflow-com-security.txt