generated: '2026-09-13' method: probed source: live probes 2026-09-13 provider: iDenfy providerId: idenfy published: false security_txt: false bug_bounty: false disclosure_page: false detail: >- iDenfy publishes no vulnerability disclosure programme that we could find. /.well-known/security.txt returns 404 on all four hosts (idenfy.com, www.idenfy.com, ivs.idenfy.com, documentation.idenfy.com); 0-working/probe-security-programs.py found no HackerOne, Bugcrowd or Intigriti presence and no disclosure page; and the 84-page documentation tree, walked live through iDenfy's own MCP server, contains no security-reporting page — only /security/callback-signing and /security/ip-whitelisting, both of which are integration-hardening guides rather than a disclosure channel. evidence: - url: https://idenfy.com/.well-known/security.txt status: 404 - url: https://www.idenfy.com/.well-known/security.txt status: 404 - url: https://ivs.idenfy.com/.well-known/security.txt status: 404 - url: https://documentation.idenfy.com/.well-known/security.txt status: 404 contact_fallback: email: support@idenfy.com portal: https://idenfy-ivs.atlassian.net/servicedesk/customer/portal/1 note: >- General support channels, not a security-reporting channel. Recorded as a fallback only; this artifact does NOT assert that iDenfy runs a disclosure programme.