generated: '2026-08-02' method: searched probe: true source: https://www.picussecurity.com/trust-center policy: - https://www.picussecurity.com/trust-center contact: - info@picussecurity.com program: name: PICUS Vulnerability Disclosure Program type: vulnerability-disclosure-program bug_bounty: false bounty_platform: null intake: web-form intake_note: >- "If you believe you have discovered a vulnerability, please reach out to us by filling out the report below" — the program is served from the Vulnerability Disclosure Program section of the Picus Trust Center and collects reports through an embedded form rather than a published security address. coordinated_disclosure: true disclosure_terms: >- "We kindly request to adhere to a waiting period before publicly disclosing any vulnerabilities you might have found." No fixed embargo window is published. scope_statement: >- "This program provides detailed information about the systems and research areas covered, along with instructions on how to submit vulnerability reports." security_txt: present: false probed: - path: https://www.picussecurity.com/.well-known/security.txt status: 404 - path: https://picussecurity.com/.well-known/security.txt status: 404 - path: https://api.picussecurity.com/.well-known/security.txt status: 404 - path: https://apidocs.picussecurity.com/.well-known/security.txt status: 404 evidence: - source: https://www.picussecurity.com/trust-center kind: vulnerability-disclosure-page http_status: 200 fetched: '2026-08-02' gaps: - No RFC 9116 /.well-known/security.txt on any Picus host. - No dedicated security@ contact address published. - No named bug bounty platform (HackerOne / Bugcrowd / Intigriti) and no published safe-harbor language.