generated: '2026-08-25' method: probed source: live probes of /.well-known/security.txt on every host plus a search of kantata.com and the knowledge base checked: '2026-08-25' program_found: false security_txt: false bug_bounty: false disclosure_policy: false security_contact: null note: >- No vulnerability disclosure surface was found. /.well-known/security.txt returns 404 on api.mavenlink.com, app.mavenlink.com, developer.kantata.com, www.kantata.com and knowledge.kantata.com (www.mavenlink.com answers 200 with a Next.js SPA shell for every path, which is not a document). There is no /security page on kantata.com (404), no HackerOne, Bugcrowd or Intigriti program, and no responsible-disclosure or security contact address published on the Trust Center. The only security-adjacent public fact is a named CISO on the Trust Center page. This is a recorded absence, not a failed probe - NO `Security` or `SecurityTxt` pointer is emitted. probed: - url: https://api.mavenlink.com/.well-known/security.txt status: 404 - url: https://app.mavenlink.com/.well-known/security.txt status: 404 - url: https://developer.kantata.com/.well-known/security.txt status: 404 - url: https://www.kantata.com/.well-known/security.txt status: 404 - url: https://knowledge.kantata.com/.well-known/security.txt status: 404 - url: https://www.kantata.com/security status: 404 - url: https://trust.kantata.com status: 0