generated: '2026-08-17' method: searched probe: true program_published: false policy: [] contact: - security@launchmetrics.com bug_bounty: null note: >- Launchmetrics publishes NO vulnerability disclosure programme. The automated probe (0-working/probe-security-programs.py) returned vdp=none, and manual checks confirm it: there is no /.well-known/security.txt on any host, no /security, /responsible-disclosure or /vulnerability-disclosure page we could reach, and no HackerOne, Bugcrowd or Intigriti listing. The one security address the company does publish is security@launchmetrics.com, named in the General Terms of Use — but read the framing before treating it as a disclosure channel: it is offered for customers to report a compromise of their OWN account ("You must notify Launchmetrics immediately at security@launchmetrics.com of any breach of security or unauthorized use of your Account"), not as an intake for third-party vulnerability reports. There is no stated scope, no safe harbour, no response SLA and no coordinated-disclosure commitment. Because there is no programme, NO `Security` or `VulnerabilityDisclosure` pointer is wired into apis.yml. This file records a measured absence plus the one contact that does exist, so a security researcher has somewhere to start. caveat: >- www.launchmetrics.com is behind a SiteGround bot challenge for our egress IP (HTTP 202 + sg-captcha on every path), so a disclosure page published only on the marketing site could not be read on this pass. Everything else on the estate was reachable and checked. evidence: - source: https://connect.launchmetrics.com/Home/en/GeneralTerms status: 200 kind: terms-of-use finding: security@launchmetrics.com published as the account-compromise notification address. - source: https://nap.launchmetrics.com/.well-known/security.txt status: 404 kind: security.txt - source: https://careers.launchmetrics.com/.well-known/security.txt status: 404 kind: security.txt - source: https://help.launchmetrics.com/.well-known/security.txt status: 404 kind: security.txt - source: https://launchmetrics.com/.well-known/security.txt status: 202 kind: security.txt finding: sg-captcha challenge stub, not a document. - source: https://trust.launchmetrics.com/ status: 000 kind: trust-center finding: DNS does not resolve. - source: https://security.launchmetrics.com/ status: 000 kind: trust-center finding: DNS does not resolve. recommendation_to_provider: >- Publishing an RFC 9116 /.well-known/security.txt on launchmetrics.com and nap.launchmetrics.com, pointing at a short disclosure policy, would close the highest-value gap on this estate for a few hours of work.