generated: '2026-08-13' method: searched probe: true source: https://kudobuzz.com/security notes: >- The automated probe (0-working/probe-security-programs.py) returns no hit for Kudobuzz, because it requires bug-bounty / "responsible disclosure" / security@ keywords. Reading the Kudobuzz security policy page directly does find one real thing the probe misses: a named contact published specifically for disclosures. That is recorded below. It is a security CONTACT, not a vulnerability disclosure PROGRAM — there is no policy document, no scope statement, no safe-harbour language, no response-time commitment, no bug bounty and no security.txt. Do not read this artifact as Kudobuzz operating a VDP. disclosure_program: false policy_published: false safe_harbour: false bug_bounty: false contact_published: true contact: - kind: email value: help@kudobuzz.com role: Security Team, Kudobuzz published_at: https://kudobuzz.com/security dedicated: false note: >- Kudobuzz routes security disclosures to its general help address rather than a dedicated security@ mailbox. The address is Cloudflare email-obfuscated on the page and was decoded from the data-cfemail attribute. quote: >- "For security concerns, disclosures, or questions about this policy, contact: Security Team, Kudobuzz, help@kudobuzz.com" security_policy: url: https://kudobuzz.com/security last_updated_by_provider: September 2025 covers: - Security principles (confidentiality, integrity, availability) - Data encryption in transit (TLS/SSL) and at rest - Role-based access control with enforced MFA for internal admin access - Code review, penetration tests and vulnerability scans before deployment - Firewalls, intrusion detection and monitoring - Data retention and secure disposal - Sub-processor review (list available on request, not published) - Incident response — investigate, contain, notify without undue delay, post-incident review - Merchant responsibilities and a liability disclaimer see: security/kudobuzz-trust-center.yml probed: - url: https://kudobuzz.com/.well-known/security.txt status: 404 - url: https://kudobuzz.com/security.txt status: 404 - url: https://kudobuzz.com/responsible-disclosure status: 404 - url: https://kudobuzz.com/security/responsible-disclosure status: 404 - url: https://kudobuzz.com/vulnerability-disclosure status: 404 - url: https://api.kudobuzz.com/.well-known/security.txt status: 404 - url: https://kudobuzz.com/security status: 200 bounty_platforms_checked: - platform: HackerOne result: no Kudobuzz program referenced on any Kudobuzz page - platform: Bugcrowd result: no Kudobuzz program referenced on any Kudobuzz page - platform: Intigriti result: no Kudobuzz program referenced on any Kudobuzz page gaps: - No RFC 9116 /.well-known/security.txt on kudobuzz.com or api.kudobuzz.com - No written vulnerability disclosure policy or reporting process - No safe-harbour statement for good-faith researchers - No dedicated security@ address; disclosures share the general support inbox - No published triage or response-time commitment - No bug bounty program evidence: - source: https://kudobuzz.com/security kind: security-policy-page keywords: [disclosures, security concerns, Security Team, incident response] checked: '2026-08-13'