generated: '2026-07-19' method: searched probe: true source: https://trust.joinhandshake.com/ policy: - https://joinhandshake.com/security contact: - security@joinhandshake.com disclosure: report_url: https://trust.joinhandshake.com/ responsible_disclosure: available upon request via the trust portal evidence: - source: https://trust.joinhandshake.com/ kind: trust-center-disclosure detail: '"Report a vulnerability" contact with security@joinhandshake.com' - source: https://joinhandshake.com/security kind: security-page notes: >- Handshake's trust center exposes a "Report a vulnerability" flow and a security contact (security@joinhandshake.com). No public bug-bounty program (HackerOne / Bugcrowd / Intigriti) was found. The Wolfia-vendored /.well-known/security.txt served at trust.joinhandshake.com is the trust-center platform's own file (Canonical wolfia.com), not Handshake's, so it is not indexed as Handshake's SecurityTxt.