generated: '2026-09-19' method: searched probe: true source: well-known/live-direct-marketing-online-security.txt policy: - https://developers.live-direct-marketing.online/legal/security contact: - mailto:welcome@live-direct-marketing.online - mailto:security@ldm.delivery (stated on the developer-portal security page; the ldm.delivery domain does not resolve) evidence: - source: well-known/live-direct-marketing-online-security.txt kind: security.txt url: https://live-direct-marketing.online/.well-known/security.txt http_status: 200 fields: - Contact - Expires 2027-05-06 - Preferred-Languages en, ru - Canonical - Policy - source: https://live-direct-marketing.online/security kind: policy page named by security.txt http_status: 404 note: 'The Policy: URL in the provider''s own security.txt is dead.' - source: https://developers.live-direct-marketing.online/legal/security kind: disclosure statement http_status: 200 quote: To report a vulnerability, please email security@ldm.delivery. We follow responsible disclosure and will respond within 72 hours. note: 'A complete overview of security practices "is being prepared". The stated mailbox domain ldm.delivery has no DNS record (curl: Could not resolve host), so the only working contact is the security.txt one.' - source: https://api.live-direct-marketing.online/api/legal/documents/security kind: API-served security overview http_status: 200 note: Five-point draft v0 in Russian (TLS, role-based access, no secrets in source, protected suppression storage, per-tenant DB isolation); no disclosure process. docs: https://developers.live-direct-marketing.online/legal/security policy_declared_in_security_txt: https://live-direct-marketing.online/security response_commitment: '"We follow responsible disclosure and will respond within 72 hours." — https://developers.live-direct-marketing.online/legal/security' bug_bounty: false note: 'A disclosure channel exists and is verifiable (RFC 9116 security.txt with a valid Contact and a 72-hour response statement on the developer portal), but both published policy locations are broken in different ways: the security.txt Policy URL 404s and the portal names a mailbox on an unregistered domain. No bug bounty platform. No trust center found (probe-security-programs.py: trust=none).'