generated: '2026-08-04' method: probed probe: true description: >- Niural publishes no vulnerability disclosure channel. There is no /.well-known/security.txt on any host, no responsible-disclosure or security policy page on niural.com, and no program on HackerOne, Bugcrowd or Intigriti was found. Recorded as a verified zero — no Security pointer is wired, because there is nothing to point at. policy: [] contact: [] bug_bounty: null evidence: - {source: 'https://www.niural.com/.well-known/security.txt', http_status: 404} - {source: 'https://niural.com/.well-known/security.txt', http_status: 404} - {source: 'https://docs.niural.com/.well-known/security.txt', http_status: 404} - {source: 'https://api-sandbox.niural.com/.well-known/security.txt', http_status: 403, note: 'API Gateway rejects unrouted paths'} - {source: 'https://www.niural.com/security', http_status: 404} - {source: 'https://www.niural.com/security-and-compliance', http_status: 404} gaps: - A payroll and money-movement platform with SOC 2 Type II has no published way for a researcher to report a vulnerability. An RFC 9116 security.txt at https://www.niural.com/.well-known/security.txt naming a security@ address and a policy URL is the smallest possible fix.