generated: '2026-07-22' method: searched probe: true policy: - https://www.morningstar.com/company/vulnerability-disclosure contact: - security@morningstar.com bug_bounty: - https://bugcrowd.com/MorningStar evidence: - source: https://www.morningstar.com/company/vulnerability-disclosure kind: vulnerability-disclosure-program note: Official VDP page - accepts reports at security@morningstar.com (anonymous submissions allowed), acknowledges within 3 business days, and grants CFAA safe-harbor authorization for good-faith research. Direct fetch returns an HTTP 202 bot-challenge; content verified via search-engine indexed text. - source: https://bugcrowd.com/MorningStar kind: bug-bounty-platform note: Bugcrowd program profile page (HTTP 200; JS-rendered shell, program scope not verifiable anonymously). notes: /.well-known/security.txt is not published on any Morningstar host (404 on www.morningstar.com, agents.morningstar.com, byallaccounts.net; 403 on us-api.morningstar.com; SPA shell on developer.morningstar.com).