generated: '2026-08-17' method: searched probe: true source: https://api.lengow.io/.well-known/security.txt canonical: https://my.lengow.io/.well-known/security.txt contact: - mailto:security@lengow.com policy: [] encryption: https://my.lengow.io/.well-known/publickey.txt preferred_languages: - en - fr expires: '2023-09-08T05:49:00.000Z' expired: true bug_bounty: program: false statement: >- "Lengow does not have a bug bounty/reward program and will therefore not offer paid bug/security rewards. We might however offer a token of our appreciation to security researchers who take the time and effort to investigate and report security vulnerabilities to us." — Lengow Security Team, verbatim from the served security.txt platforms_checked: - HackerOne - Bugcrowd - Intigriti platforms_found: [] note: >- Lengow serves a real RFC 9116 security.txt from two hosts, with a named security contact, a PGP key location and an explicit bug-bounty posture. Two gaps: the `Expires` value is 2023-09-08, so the document is stale by RFC 9116's own rule, and there is no `Policy:` field pointing at a disclosure policy page (/security and /security/responsible-disclosure both 404 on www.lengow.com). Refreshing Expires and adding a Policy URL is the cheapest fix available to this provider. evidence: - source: https://api.lengow.io/.well-known/security.txt status: 200 kind: security.txt - source: https://my.lengow.io/.well-known/security.txt status: 200 kind: security.txt (canonical, byte-identical) - source: https://www.lengow.com/security/ status: 404 kind: disclosure page probe - source: https://www.lengow.com/.well-known/security.txt status: 404 kind: security.txt probe on the marketing host