generated: '2026-08-13' method: searched probe: true source: https://trust.leandata.com/ description: >- LeanData publishes a Responsible Disclosure program on its SafeBase trust center, listed as an enabled control with full maturity and a HackerOne integration flag set. That is a real, provider-published disclosure posture — but it is reachable only as an item inside a JavaScript-rendered trust portal. There is no RFC 9116 security.txt on any LeanData host, no standalone /responsible-disclosure page, and no published security@ contact address, so an automated scanner or an agent looking for where to report a vulnerability will find nothing. The program exists; its discovery surface does not. policy: - https://trust.leandata.com/?itemUid=64c9680b-ef79-4c92-baa0-13b541954bef contact: [] security_txt: false bug_bounty: platform_integration_advertised: hackerone program_url: null note: >- The trust center's control record carries integrations.hackerone.allowed = true. LeanData does not publish a public HackerOne program URL and none was found, so this is recorded as an advertised integration capability, not a confirmed public bounty program. related_controls_published: - Responsible Disclosure - Vulnerability & Patch Management - Vulnerability Management Policy - Incident Response - Incident Reporting Process - Data Breach Notifications - Designated Response Personnel - Application Penetration Testing - Pentest Report - Secure Development Training - Code Analysis evidence: - source: https://trust.leandata.com/ kind: trust-center http_status: 200 fetched: '2026-08-13' detail: >- Trust-center item "Responsible Disclosure" rendered with the enabled state icon and a deep link at /?itemUid=64c9680b-ef79-4c92-baa0-13b541954bef; the underlying record carries maturity "full". - source: https://www.leandata.com/.well-known/security.txt kind: probe http_status: 404 fetched: '2026-08-13' - source: https://api.leandata.com/.well-known/security.txt kind: probe http_status: 404 fetched: '2026-08-13' - source: https://mcp.leandata.com/.well-known/security.txt kind: probe http_status: 404 fetched: '2026-08-13' - source: https://www.leandata.com/responsible-disclosure/ kind: probe http_status: 404 fetched: '2026-08-13' - source: https://trust.leandata.com/responsible-disclosure kind: probe http_status: 404 fetched: '2026-08-13' recommendation: >- Publish /.well-known/security.txt on www.leandata.com, api.leandata.com and mcp.leandata.com with Policy: pointing at the trust-center disclosure item and Contact: a security@leandata.com address. It is a five-line file and it is the difference between a disclosure program that exists and one that can be found.