generated: '2026-08-25' method: probed source: >- /.well-known/security.txt probes on www.metricstream.com, assets.metricstream.com and info.metricstream.com; searches of hackerone.com, bugcrowd.com and intigriti.com; and the MetricStream Trust Center and Security Standards document — all 2026-08-25. summary: >- MetricStream publishes NO coordinated vulnerability disclosure channel. There is no /.well-known/security.txt on any host, no bug bounty or VDP program on HackerOne, Bugcrowd or Intigriti, and no security@ contact or disclosure policy page on the site. The only security contact surfaced anywhere is the `iodef "mailto:support@metricstream.com"` entry in the company's own DNS CAA record — which is a certificate-misissuance reporting address, not a vulnerability disclosure channel, and should not be treated as one. No `Security` pointer is emitted in apis.yml: the check asserts the provider publishes a disclosure program, and MetricStream does not. program_found: false security_txt: false bug_bounty: false disclosure_policy_page: null security_contact: null probes: - url: https://www.metricstream.com/.well-known/security.txt status: 404 - url: https://assets.metricstream.com/.well-known/security.txt status: 404 - url: https://info.metricstream.com/.well-known/security.txt status: 404 related_but_not_a_vdp: - source: DNS CAA record for metricstream.com value: 0 iodef "mailto:support@metricstream.com" note: certificate-authority incident reporting only - source: https://assets.metricstream.com/pdf/security-standards-metricstream-cloud-v1.pdf note: >- Publishes internal vulnerability-management SLAs and a 48-hour incident notification commitment to CUSTOMERS, but no inbound channel for a third-party researcher. gap: >- MetricStream sells IT & Cyber Risk and Cyber Threat & Vulnerability Management software. An RFC 9116 security.txt naming a Contact and a Policy would take an afternoon and would close the most visible gap between its own posture and the practice it sells to its customers.