generated: '2026-08-04' method: searched probe: true source: https://lemon.me/.well-known/security.txt contact: - mailto:cybersecuri@lemon.me policy: [] program: type: informal bug bounty intake formal_platform: null platforms_checked: [HackerOne, Bugcrowd, Intigriti] platforms_found: [] submission: 'Email cybersecuri@lemon.me with the exact subject "BugBounty" — the file states the subject line is exclusive to this program.' stated_commitment: '"Share your knowledge with our team, we''re going to answer all communications quickly and with respect and absolute confidentiality."' safe_harbor_published: false scope_published: false rewards_published: false rfc9116: conforms: partial present_fields: [Contact] missing_fields: [Expires, Encryption, Policy, Preferred-Languages, Canonical] note: >- Expires is REQUIRED by RFC 9116; it is absent. The Contact value also embeds instructions ("and subject: BugBounty --> (subject exclusive)") after the mailto URI, which is not a valid Contact field value. related_channels: - {name: Report theft or loss of device/account, url: 'https://report.lemon.me/'} - {name: Report scams/fraud, url: 'https://form.jotform.com/242806351092655'} - {name: Law-enforcement / authority requests, url: 'https://eu.jotform.com/form/231774405436659'} evidence: - source: well-known/lemon-cash-security.txt kind: security.txt (harvested verbatim) - source: https://lemon.me/.well-known/security.txt kind: live fetch http_status: 200 content_type: text/plain;charset=utf-8 pages_checked: - {url: 'https://lemon.me/security', http_status: 404} - {url: 'https://lemon.me/compliance', http_status: 404} - {url: 'https://trust.lemon.me', result: DNS does not resolve} - {url: 'https://security.lemon.me', result: DNS does not resolve} x-evidence: fetched: '2026-08-04' url: https://lemon.me/.well-known/security.txt http_status: 200