generated: '2026-08-12' method: probed probe: true source: live probes of kartra.com security/disclosure paths and /.well-known/security.txt found: false policy: [] contact: [] bug_bounty: null evidence: - {url: 'https://kartra.com/.well-known/security.txt', status: 404} - {url: 'https://kartra.com/security.txt', status: 404} - {url: 'https://kartra.com/security/', status: 404} - {url: 'https://app.kartra.com/.well-known/security.txt', status: 403} - {url: 'https://api.kartra.com/.well-known/security.txt', status: 403} - {url: 'https://trust.kartra.com/', status: 307, note: 'redirects to https://app.kartra.com/dashboard — a wildcard-subdomain catch-all into the product, not a trust centre'} note: >- Kartra publishes no vulnerability disclosure policy, no responsible-disclosure page and no bug bounty programme on HackerOne, Bugcrowd or Intigriti. There is no security@ address; the only published contact for security and compliance matters is the general info@kartra.com, offered on the GDPR page for requesting PCI DSS audit documentation. The 200 at support.kartra.com/.well-known/security.txt belongs to Intercom, Kartra's help centre vendor, and is not Kartra's programme — see well-known/kartra-well-known.yml. No Security or VulnerabilityDisclosure pointer is emitted from this artifact, because there is nothing to point at. recorded_absence: true