generated: '2026-07-26' method: searched probe: true source: https://www.nesto.ca/security/ policy: - https://www.nesto.ca/security/ - https://www.nesto.ca/.well-known/security.txt - https://www.nesto.ca/contact/ contact: - mailto:security@nesto.ca - mailto:support@nesto.ca - https://www.nesto.ca/contact/ encryption: https://www.nesto.ca/.well-known/pgp-key.txt preferred_languages: [en, fr] scope: - '*.nesto.ca' - Web applications, APIs, and customer-facing services bug_bounty: offered: false platform: null statement: >- "we do not offer compensation for vulnerability disclosures" — nesto.ca/security/. The security.txt adds: "We might not send you a bounty, but we *will* send gratitude, respect, and fast fixes." safe_harbor: published: false note: >- No explicit legal safe-harbour language. The published expectation is: "Please report vulnerabilities privately and give us a reasonable time to investigate before public disclosure." gaps: - security.txt has no `Expires:` field (RFC 9116 requires it) - 'Policy: points at a generic contact form rather than a dedicated disclosure policy page' - The security.txt Contact is support@nesto.ca while the /security/ page routes to security@nesto.ca — two different intake addresses for the same program - No CVD program page, no acknowledgements/hall-of-fame, no response SLA evidence: - source: https://www.nesto.ca/.well-known/security.txt kind: security.txt (live probe, HTTP 200) - source: https://www.nesto.ca/security/ kind: first-party security policy page (HTTP 200) keywords: [report a security issue, security@nesto.ca, we do not offer compensation] - source: well-known/nesto-security.txt kind: harvested security.txt