generated: '2026-09-19' method: searched source: https://raw.githubusercontent.com/MoltyCel/moltrust-api/main/README.md + https://moltrust.ch/terms.html + well-known probes 2026-09-19 + probe-security-programs.py (vdp=none trust=none) checked: '2026-09-19' summary: MolTrust publishes a first-party security contact - security@moltrust.ch, in the "Contact" section of the public moltrust-api GitHub README - but no /.well-known/security.txt on any host, no security or responsible-disclosure page on moltrust.ch, no SECURITY.md in the repo, and no bug bounty. The channel is real and first-party; the program around it is undocumented. probe-security-programs.py found nothing because it does not read GitHub READMEs. program: published: true kind: email-only contact: mailto:security@moltrust.ch quote: '"## Contact\nsecurity@moltrust.ch"' location: https://github.com/MoltyCel/moltrust-api#readme secondary_contact: 'info@moltrust.ch for compromised API keys (Terms of Service section 3: "If you suspect your API key has been compromised, contact us immediately at info@moltrust.ch")' policy: page: null safe_harbor_documented: false scope_documented: false response_sla_documented: false disclosure_timeline_documented: false rewards: none-published bug_bounty: platform: null hackerone: false bugcrowd: false intigriti: false note: No bounty program located on any MolTrust host or the major platforms. security_txt: served: false probes: - url: https://moltrust.ch/.well-known/security.txt status: 404 - url: https://moltrust.ch/security.txt status: 404 - url: https://api.moltrust.ch/.well-known/security.txt status: 404 - url: https://uresolver.moltrust.ch/.well-known/security.txt status: 404 - url: https://status.moltrust.ch/.well-known/security.txt status: 404 note: RFC 9116 is not implemented. A security.txt naming the existing security@moltrust.ch address would be a one-file fix on a static nginx host. security_md: probes: - url: https://raw.githubusercontent.com/MoltyCel/moltrust-api/main/SECURITY.md status: 404 - url: https://raw.githubusercontent.com/MoltyCel/.github/main/SECURITY.md status: 404 public_security_record: note: The moltrust-api repo publishes an incident write-up (docs/incidents/2026-05-22_test-key-exposure.md), a security_check.sh script, dependency-pinning and PQC dual-signature ADRs, and a blog post "Hardening the MolTrust Trust Stack" (2026-03-26). Evidence of practice, not a disclosure policy. pointer_basis: Security pointer emitted on the strength of the published first-party security@moltrust.ch contact; it asserts a disclosure channel exists, not a policy.