generated: '2026-07-17' method: searched probe: true source: https://portone.io/ contact: - mailto:infra@portone.io evidence: - source: dns:_dmarc.portone.io kind: DMARC rua/ruf contact (live probe) note: DMARC record publishes rua=mailto:infra+dmarc@portone.io / ruf=mailto:infra+dmarc@portone.io. - source: https://portone.io/.well-known/security.txt kind: security.txt probe note: Not found (HTTP 404) at probe time; no RFC 9116 security.txt published. notes: >- No published .well-known/security.txt and no dedicated public vulnerability disclosure / bug-bounty page were found for PortOne at review time. The only machine-discoverable security-adjacent contact is the infrastructure address surfaced via the portone.io DMARC record (infra@portone.io). Security reports should be routed there or via PortOne developer support until a formal VDP is published. This artifact records the absence honestly rather than inventing a disclosure program.