generated: '2026-08-13' method: probed result: none program_published: false pointer_emitted: false policy: [] contact: [] source: live probes on 2026-08-13 probes: - {url: 'https://hustle.com/.well-known/security.txt', status: 404} - {url: 'https://api.hustle.com/.well-known/security.txt', status: 404} - {url: 'https://hustle.com/responsible-disclosure/', status: 404} - {url: 'https://hustle.com/security/responsible-disclosure/', status: 404} - {url: 'https://hustle.com/vulnerability-disclosure/', status: 404} - {url: 'https://hackerone.com/hustle', status: 404} - {url: 'https://bugcrowd.com/hustle', status: 200, verdict: 'false positive — generic "Bugcrowd Hacker Portal" SPA shell, no Hustle program'} - {url: 'https://hustle.com/security/', status: 200, verdict: 'security posture page, not a disclosure policy'} notes: >- Hustle publishes NO vulnerability disclosure program. https://hustle.com/security/ returns 200 and describes a defense-in-depth architecture, SOC 2 / CSA STAR compliance, penetration testing and vulnerability scanning, but it names no reporting channel: there is no security@ address, no PGP key, no disclosure policy, no safe-harbour language and no bug-bounty listing. The automated probe initially flagged this page on the keywords "vulnerability" (from "Vulnerability Scanning") and "security issue" (from an internal-communication sentence) — that is a keyword collision, not a disclosure program, so this file records the absence and NO `VulnerabilityDisclosure` or `Security` pointer is wired into apis.yml. The company's only published contacts are the general support/sales addresses in the site footer. This is a concrete, provider-fixable gap: an RFC 9116 /.well-known/security.txt would close it. checked: '2026-08-13'