generated: '2026-08-17' method: searched probe: true url: https://trust.go-electra.com/ description: >- Electra runs a real, publicly linked trust centre. It is the "Security" entry in the site footer on www.go-electra.com and it resolves to a Vanta-hosted trust report on Electra's own subdomain. The automated probe (0-working/probe-security-programs.py) recorded trust=none because it requires trust/compliance keywords in the served body, and Vanta serves a 4.8KB HTML shell that renders its content client-side from a signed bundle — so the presence of the trust centre is verified, but its contents are not readable anonymously. platform: Vanta platform_evidence: slug_id: 29bokoh51ag58ypkefl6z3 og_image: https://app.eu.vanta.com/doc?s=telu03zq9am1bikvdmnesj bundle_host: assets.vanta.com region: eu certifications: [] certifications_note: >- NO certification is asserted. The page title is "Electra Trust Center" and nothing else in the served markup names ISO 27001, SOC 2, PCI DSS, HIPAA, FedRAMP or GDPR. Attempts to read the underlying report data anonymously all failed: app.eu.vanta.com/api/trust/, app.eu.vanta.com/trust/ and app.vanta.com/api/trust/ each returned the same HTML shell, and app.eu.vanta.com/graphql rejected an anonymous query with HTTP 400 "Missing `signature` or `signedAt`". Because no certification is readable, no `Compliance` pointer is emitted in apis.yml. evidence: - source: https://www.go-electra.com/en/ kind: footer-link http_status: 200 detail: >- Footer anchor `Security` in the legal/help column, alongside Assistance, Contact, General T&C, Privacy Policy and Ethics. fetched: '2026-08-17' - source: https://trust.go-electra.com/ kind: trust-center http_status: 200 content_type: text/html detail: >- 4,866-byte Vanta trust-report shell; Electra Trust Center; data-slugid="29bokoh51ag58ypkefl6z3". fetched: '2026-08-17' - source: https://app.eu.vanta.com/graphql kind: negative http_status: 400 detail: 'Anonymous query rejected: Missing `signature` or `signedAt`.' fetched: '2026-08-17' gaps: - >- No vulnerability disclosure or responsible-disclosure policy is published. /.well-known/security.txt returned 404 on go-electra.com, backend.go-electra.com and ocpi.go-electra.com. The only reporting channel Electra publishes is its ethics/whistleblowing page (https://www.go-electra.com/en/whistleblowing-and-grievance/, ethics@go-electra.com, anonymous Google Forms, postal mail to VP Legal), which is explicitly scoped to the Code of Conduct, corruption and harassment — it names no security contact and no bug bounty. Consequently no `Security` / `VulnerabilityDisclosure` artifact or pointer is emitted, and the security_disclosure check is a genuine miss rather than an unrecorded one. - >- A security researcher who found a flaw in the OCPI surface has no published address to send it to. Adding a security.txt on go-electra.com and ocpi.go-electra.com, and surfacing the disclosure policy that almost certainly already exists inside the Vanta trust centre, is the single cheapest fix on this profile.