generated: '2026-09-07' method: probed probe: true published: false source: >- 0-working/probe-security-programs.py plus direct GETs of /.well-known/security.txt on connect.plumma.it (404), www.plumma.it (403 object-store default), connect.ploomma.com (200 SPA shell, soft-404 control failed) and core.ploomma.com (404); plus a read of the provider's Security & Compliance document at https://connect.plumma.it/plumma-connect-docs/#security policy: [] contact: [] bug_bounty: null note: >- NO COORDINATED-DISCLOSURE ROUTE IS PUBLISHED. There is no RFC 9116 security.txt on any Plumma host, no /security, /responsible-disclosure or /vulnerability-disclosure page, and no HackerOne, Bugcrowd or Intigriti program. The Security & Compliance document is substantial on posture — AWS WAF, VPC segregation, MFA for administrative access, SAST in the pipeline, annual external penetration testing — but it names no channel for a third party to report a vulnerability and no security@ address. The only published contacts are info@plumma.it (general) and support@plumma.it (SLA support), neither presented as a security channel. No `Security` pointer is emitted; recording an absence is the finding. evidence: - {source: 'https://connect.plumma.it/.well-known/security.txt', status: 404} - {source: 'https://www.plumma.it/.well-known/security.txt', status: 403, note: 'object-store AccessDenied XML, returned for every path including a negative control'} - {source: 'https://core.ploomma.com/.well-known/security.txt', status: 404} - {source: 'https://connect.ploomma.com/.well-known/security.txt', status: 200, note: 'SPA catch-all — identical 1825-byte index.html for every path, negative control also 200; not a document'} - {source: 'https://connect.plumma.it/plumma-connect-docs/#security', status: 200, note: 'Security & Compliance V1.1 — posture only, no disclosure channel'}