generated: '2026-09-19' method: searched probe: true source: https://gitlab.com/polycode-projects/marginalia/-/blob/main/_developers/ETHICS.md policy: [] contact: [antony@polycode.co.uk] bug_bounty: null evidence: - source: https://gitlab.com/polycode-projects/marginalia/-/blob/main/_developers/ETHICS.md http_status: 200 kind: docs quote: 'Where to ask questions — Operator contact: antony@polycode.co.uk ... Issues, security disclosures, GDPR requests: email above.' - source: https://marginalia.polycode.co.uk/.well-known/security.txt http_status: 403 kind: security.txt note: Not served. probed: - {url: 'https://marginalia.polycode.co.uk/.well-known/security.txt', status: 403} - {url: 'https://marginalia.polycode.co.uk/security', status: 200, note: SPA shell (soft-404)} - {url: 'https://polycode.co.uk/.well-known/security.txt', status: 0, note: host does not resolve} note: >- A published channel, not a programme: the operator's public ETHICS.md names a single email for "issues, security disclosures, GDPR requests" and there is no security.txt, no disclosure policy page, no safe-harbour statement and no bounty. probe-security-programs.py recorded vdp=none because it looks for policy pages on the web host; the channel lives in the source repository. Recorded as a thin but real disclosure contact.