generated: '2026-08-26' method: probed source: live probes 2026-08-26 present: false security_txt: false bug_bounty: false disclosure_page: false note: >- No vulnerability disclosure surface could be verified. /.well-known/security.txt is absent from every host that answered (api.eu.ppro.com 404, api.sandbox.eu.ppro.com 404, mcp.eu.ppro.com 404); developerhub.ppro.com returns HTTP 200 for that path but the body is the ReadMe single-page-app HTML shell, not an RFC 9116 document, so it is a miss. www.ppro.com answers every /.well-known/ path with a Cloudflare "Just a moment..." interstitial (403), so a security.txt there could neither be confirmed nor ruled out. No HackerOne, Bugcrowd or Intigriti program was found, and the developer hub publishes no responsible-disclosure page. Because nothing was verified, NO Security pointer is wired in apis.yml. evidence: - url: https://api.eu.ppro.com/.well-known/security.txt status: 404 - url: https://api.sandbox.eu.ppro.com/.well-known/security.txt status: 404 - url: https://mcp.eu.ppro.com/.well-known/security.txt status: 404 - url: https://developerhub.ppro.com/.well-known/security.txt status: 200 note: HTML SPA shell (765KB), not a security.txt — treated as absent - url: https://www.ppro.com/.well-known/security.txt status: 403 note: Cloudflare bot interstitial — unreadable, not a confirmed absence