name: Nucleus Security Vulnerability Disclosure description: >- Nucleus Security publishes an RFC 9116 security.txt on its primary domain pointing at a named vulnerability disclosure program page and a dedicated security contact address. generated: '2026-08-26' method: probed source: https://nucleussec.com/.well-known/security.txt x-evidence: - url: https://nucleussec.com/.well-known/security.txt http_status: 200 content_type: text/plain fetched: '2026-08-26' - url: https://nucleussec.com/vulnerability-disclosure-program/ http_status: 200 fetched: '2026-08-26' security_txt: served: true file: well-known/nucleus-security-security.txt canonical: https://nucleussec.com/.well-known/security.txt expires: '2029-08-19T00:00:00Z' preferred_languages: en policy: - https://nucleussec.com/vulnerability-disclosure-program/ contact: - mailto:security@nucleussec.com disclosure_program: published: true url: https://nucleussec.com/vulnerability-disclosure-program/ named_platform: null bug_bounty: false note: >- A first-party vulnerability disclosure program page, not a HackerOne/Bugcrowd/Intigriti hosted bounty. No public bounty listing was found for Nucleus Security on any of those platforms during this pass. Note that Nucleus Security integrates WITH HackerOne and Bugcrowd as scan-data connectors (both appear as components on its status page) - that is a product integration, not a bounty program of its own. third_party_assurance: penetration_test: published: true document: Nucleus Security August 2025 WebApp PenTest via: https://trust.nucleussec.com/