generated: '2026-08-26' method: probed source: 'live probes of /.well-known/security.txt on every MyCarrier host, plus https://trust.mycarrier.io/ and the developer.mycarrier.io documentation index' present: false security_txt: false bug_bounty: false disclosure_page: false security_contact: null note: 'No vulnerability disclosure surface was found. /.well-known/security.txt returns 404 on go.mycarrier.io, api.mycarriertms.com and developer.mycarrier.io, and returns the site''s SPA catch-all (identical to a control probe) on mycarriertms.com — i.e. no security.txt is served anywhere. No responsible-disclosure or bug-bounty page was found on the marketing site, the developer portal or in llms.txt, and no HackerOne/Bugcrowd/Intigriti program was found. The Vanta trust center at trust.mycarrier.io is client-rendered, so if it carries a disclosure policy it was not machine-readable. Because nothing was verified, NO `Security` pointer is emitted in apis.yml. The only published security-adjacent contact is the general API support address support@mycarrier.io.' probes: - url: https://go.mycarrier.io/.well-known/security.txt status: 404 - url: https://api.mycarriertms.com/.well-known/security.txt status: 404 - url: https://developer.mycarrier.io/.well-known/security.txt status: 404 - url: https://mycarriertms.com/.well-known/security.txt status: 200 verdict: soft-404 SPA shell identical to control probe; not a security.txt