generated: '2026-08-13' method: probed source: giveffect.com probes + probe-security-programs.py name: Giveffect vulnerability disclosure description: >- Giveffect publishes no vulnerability disclosure policy, no security contact, no bug bounty and no security.txt. The public /security page is a data-security marketing page — it describes encryption, PCI and data-center posture, but it contains no reporting mechanism: no "report a vulnerability", no security@ address, no responsible-disclosure terms, no PGP key, no safe-harbour language. Recorded so the absence is on file with its evidence. policy_published: false policy_url: null security_contact: null bug_bounty: program: none platforms_checked: - HackerOne - Bugcrowd - Intigriti found: false security_txt: served: false probes: - url: https://www.giveffect.com/.well-known/security.txt status: 500 note: HTML error page, not a document - url: https://api.giveffect.com/.well-known/security.txt status: 404 note: JSON 404 envelope published_contacts: - email: contact@giveffect.com role: general source: https://www.giveffect.com/privacy-policy - email: support@giveffect.com role: support source: https://www.giveffect.com/privacy-policy pointer_note: >- NO `Security` pointer is emitted for this provider. A prior enrichment round wired common[].type Security to https://www.giveffect.com/security; that page was re-read on 2026-08-13 and contains no disclosure mechanism, so the pointer was removed rather than left crediting a security_disclosure the provider does not publish. The same URL remains wired as `Compliance`, which it does support (it names PCI DSS Level 1 and SSAE 16). remedy: >- Publish an RFC 9116 /.well-known/security.txt with a Contact and a Policy URL, and a short disclosure page stating scope and safe harbour. x-evidence: - url: https://www.giveffect.com/security http_status: 200 fetched: '2026-08-13' finding: >- no occurrence of "vulnerabilit", "disclos", "report a", "security@", "bug bounty" or "responsible" anywhere in the served HTML - url: https://www.giveffect.com/.well-known/security.txt http_status: 500 fetched: '2026-08-13' checked: '2026-08-13'