generated: '2026-08-17' method: probed probe: true source: security/memo-bank-domain-security.yml published_policy: false program: none note: >- Memo Bank publishes NO vulnerability disclosure policy, no responsible-disclosure page, no bug bounty and no security.txt. The one machine-readable security contact that does exist was found in DNS: the memo.bank CAA record set includes an RFC 8659 iodef entry pointing at security@memo.bank. That is a real, provider-published, verifiable reporting address, so it is recorded here - but it is a certificate-incident reporting hint, not a disclosure programme, and a researcher would only find it by querying CAA records. Because there is no published policy PAGE, no `Security` pointer is emitted in apis.yml: doing so would credit Memo Bank with a disclosure programme it does not advertise. This is deliberately recorded as an honest partial rather than upgraded. contact: - address: security@memo.bank channel: dns-caa-iodef discoverable_by: dig CAA memo.bank verified: true - address: openbanking@memo.bank channel: marketplace registration contact note: Not a security contact; recorded only to distinguish it from the address above. policy: [] bug_bounty: present: false platforms_checked: - platform: HackerOne url: https://hackerone.com/memobank status: 404 - platform: Bugcrowd url: https://bugcrowd.com/memobank status: 404 - platform: Intigriti checked: true found: false security_txt: present: false probed: - url: https://memo.bank/.well-known/security.txt status: 404 - url: https://memo.bank/security.txt status: 200 soft_404: true note: >- Returns the site's Next.js SPA shell with lang="security.txt" rather than RFC 9116 content. A naive probe that only checks the status code would wrongly credit this as a hit. - url: https://api.memo.bank/.well-known/security.txt status: 404 - url: https://api.sandbox.memo.bank/.well-known/security.txt status: 404 - url: https://docs.api.memo.bank/.well-known/security.txt status: 404 - url: https://client.memo.bank/.well-known/security.txt status: 404 disclosure_pages_probed: - url: https://memo.bank/en/responsible-disclosure/ status: 404 - url: https://memo.bank/en/vulnerability-disclosure/ status: 404 - url: https://memo.bank/en/bug-bounty/ status: 404 - url: https://memo.bank/en/about/security-operations/ status: 200 contains_disclosure_policy: false note: >- The security page describes controls (two-step authentication, TLS, encryption at rest, European hosting on GCP/AWS, GDPR, an audited core banking platform) and names the ECB/ACPR/AMF regulators, but contains no vulnerability reporting instructions, no security contact address and no safe-harbour statement. evidence: - source: security/memo-bank-domain-security.yml kind: dns-caa record: 0 iodef "mailto:security@memo.bank" domain: memo.bank probed: '2026-08-17' - source: https://memo.bank/.well-known/security.txt kind: negative-probe http_status: 404 probed: '2026-08-17' - source: https://memo.bank/security.txt kind: soft-200 http_status: 200 content_type: text/html probed: '2026-08-17' recommended_to_provider: - >- Publish /.well-known/security.txt (RFC 9116) on memo.bank and api.memo.bank with Contact, Preferred-Languages, Canonical and Expires. The contact address already exists in the CAA record, so this is a five-line file, and it is the single cheapest security-posture improvement available to them. - >- Publish a responsible-disclosure page with scope and a safe-harbour statement. As an ECB-licensed credit institution with a public payments API, Memo Bank is a higher-value research target than most, and researchers currently have no documented route in. gaps: - No RFC 9116 security.txt on any host. - No responsible-disclosure or vulnerability-disclosure page. - No bug bounty programme on any major platform. - No safe-harbour statement for good-faith researchers. - No published PGP key or Preferred-Languages hint. - The only machine-readable security contact is hidden in a DNS CAA iodef record.