generated: '2026-08-12' method: probed probe: true found: false policy: [] contact: [] note: 'No vulnerability disclosure programme could be found. Probed 2026-08-12: /.well-known/security.txt returns 404 on mapp.com and docs.mapp.com and a marketing-site soft-200 on api.mapp.com and auth.mapp.com; mapp.com/responsible-disclosure/, /security-policy/, /vulnerability-disclosure/ and /legal/security/ all return 404; hackerone.com/mapp returns 404 and bugcrowd.com/mapp resolves to the generic Bugcrowd hacker portal, not a Mapp programme. The trust centre describes vulnerability scanning and annual penetration testing but publishes no route for an outside researcher to report a finding. This is a recorded ABSENCE, and no type: Security pointer is emitted for it — the pointer would assert a disclosure surface Mapp does not serve. It is also the cheapest gap on this profile for Mapp to close: a single RFC 9116 security.txt naming security@mapp.com would do it.' evidence: - url: https://mapp.com/.well-known/security.txt http_status: 404 - url: https://docs.mapp.com/.well-known/security.txt http_status: 404 - url: https://api.mapp.com/.well-known/security.txt http_status: 200 note: HTML marketing-site shell, soft-404 - url: https://mapp.com/responsible-disclosure/ http_status: 404 - url: https://mapp.com/security-policy/ http_status: 404 - url: https://mapp.com/vulnerability-disclosure/ http_status: 404 - url: https://hackerone.com/mapp http_status: 404