generated: '2026-07-17' method: searched probe: true source: https://www.hitpayapp.com/.well-known/security.txt contact: - mailto:support@hitpayapp.com - https://hitpay.zendesk.com/hc/en-us evidence: - source: https://www.hitpayapp.com/.well-known/security.txt kind: security.txt (live probe) result: not present (308 redirect, no file served) notes: >- No published security.txt or dedicated vulnerability disclosure / bug bounty program URL was confirmed on probe. Security-relevant issues are routed through HitPay support (support@hitpayapp.com) and the Zendesk help center. This artifact records the absence honestly rather than inventing a VDP endpoint.