generated: '2026-08-13' method: probed source: >- Live probes of the standard disclosure surfaces on every Ontraport host, plus searches of ontraport.com and the major bug-bounty platforms description: >- Ontraport publishes no vulnerability disclosure program. There is no security.txt on any host, no /security page, no responsible-disclosure policy, no named security contact, and no listing on HackerOne, Bugcrowd or Intigriti. A researcher who finds a flaw in a platform that stores whole customer databases and processes card payments has no published route to report it. This is a recorded absence, not a missing probe. published: false program_type: none policy_url: null contact: null bug_bounty: exists: false platforms_checked: - hackerone - bugcrowd - intigriti - openbugbounty result: no Ontraport program found safe_harbor: not published pgp_key: not published probes: - url: https://ontraport.com/.well-known/security.txt status: 404 - url: https://ontraport.com/security.txt status: 404 - url: https://api.ontraport.com/.well-known/security.txt status: 502 note: The API edge answers 502 for any unrouted path. - url: https://mcp.ontraport.com/.well-known/security.txt status: 404 - url: https://ontraport.com/security status: 404 related_contacts_published: legal: legal@ontraport.com note: >- The only published direct address on ontraport.com/legal is legal@ontraport.com, for notices of claim and arbitration opt-out. It is not a security contact and should not be used as one. remediation: owner: provider actions: - Publish an RFC 9116 security.txt at https://ontraport.com/.well-known/security.txt with Contact, Policy, Expires and Preferred-Languages. - Publish a coordinated disclosure policy page with a safe-harbor statement. - Stand up a security@ontraport.com mailbox, or list on a disclosure platform. note: >- This is the cheapest unmet check on Ontraport's whole profile — a single static text file — and the one most out of step with a PCI DSS Level 1 claim.