generated: '2026-08-22' method: searched source: https://www.handle.com/security-and-trust/ probe: true program: bug-bounty policy: - https://www.handle.com/security-and-trust/ contact: [] submission_url: https://www.handle.com/contact-sales/ statement: >- "Bug Bounty Program. Handle offers a bug bounty program if an exploitable vulnerability is found. Click below to submit a report." — https://www.handle.com/security-and-trust/ evidence: - source: https://www.handle.com/security-and-trust/ kind: security-page http_status: 200 keywords: [bug bounty program, exploitable vulnerability, submit a report, penetration testing] - source: https://www.handle.com/.well-known/security.txt kind: security.txt http_status: 404 - source: https://hackerone.com/handle kind: bounty-platform http_status: 404 gaps: - No RFC 9116 /.well-known/security.txt on any handle.com host (probed www, api, app — all 404 or SPA shell). - No published security@ contact address. - >- The bug-bounty "Submit Report" button resolves to https://www.handle.com/contact-sales/, the general sales form — there is no dedicated intake for security researchers and no named bounty platform program (hackerone.com/handle returns 404; bugcrowd.com/handle resolves to Bugcrowd's generic hacker portal, not a Handle program).