generated: '2026-08-26' method: probed source: >- Live probes of /.well-known/security.txt on www.paubox.com, api.paubox.com and docs.paubox.com; DNS CAA lookup on paubox.com; and a review of https://www.paubox.com/security and the published https://docs.paubox.com/llms.txt documentation index. description: >- NO PUBLISHED VULNERABILITY DISCLOSURE PROGRAM FOUND. This is a recorded absence, not a gap in the probe. It is written down because it is a real finding for a company whose product is healthcare security infrastructure. program_published: false policy_url: null bug_bounty: false bug_bounty_platform: null safe_harbor_statement: null security_contact: found: true address: security@paubox.com discovered_via: >- CAA record on paubox.com — `0 iodef "mailto:security@paubox.com"`. This is a certificate-authority incident-reporting address, and it is the ONLY machine-readable security contact Paubox publishes. It is not a vulnerability disclosure policy and makes no commitment about response, scope or safe harbor. source: security/paubox-domain-security.yml evidence: - url: https://www.paubox.com/.well-known/security.txt status: 404 - url: https://api.paubox.com/.well-known/security.txt status: 404 - url: https://docs.paubox.com/.well-known/security.txt status: 404 - url: https://www.paubox.com/security status: 200 note: >- Compliance narrative page (HIPAA/HITECH, encryption, AWS platform certifications). Contains no reporting instructions, no scope statement and no safe-harbor language. - url: https://docs.paubox.com/llms.txt status: 200 note: >- Provider's own documentation index; contains no security, disclosure, responsible disclosure or bug-bounty page. recommendation: >- RFC 9116 security.txt at https://www.paubox.com/.well-known/security.txt, naming the existing security@paubox.com address and linking a disclosure policy, would turn a contact that is currently only discoverable through a DNS CAA record into a machine-readable one.