generated: '2026-09-13' method: searched probe: true source: https://www.telerik.com/.well-known/security.txt policy: - https://www.progress.com/security - https://www.progress.com/security/vulnerability-reporting-policy contact: - https://bugcrowd.com/devtools-vdp bug_bounty: platform: Bugcrowd program: DevTools VDP url: https://bugcrowd.com/devtools-vdp type: vulnerability disclosure program verified: 200 security_txt: served: true url: https://www.telerik.com/.well-known/security.txt canonical: https://www.telerik.com/.well-known/security.txt file: well-known/progress-software-security.txt expires: '2027-01-01T04:59:00.000Z' preferred_languages: en hiring: https://www.progress.com/company/careers rfc: RFC 9116 coverage_gap: 'The file is served ONLY on telerik.com and www.telerik.com. progress.com, chef.io, sharefile.com, whatsupgold.com, kemptechnologies.com, docs.progress.com and docs.chef.io all return 404 for /.well-known/security.txt (probed 2026-09-13). A researcher who finds a MOVEit or Chef issue and looks in the RFC 9116 place on the product''s own domain finds nothing — the corporate policy exists, it is simply not advertised where the standard says to look. This is the single cheapest fix available to Progress in this whole profile.' evidence: - source: https://www.telerik.com/.well-known/security.txt kind: security.txt http_status: 200 content_type: text/plain - source: https://www.progress.com/security/vulnerability-reporting-policy kind: disclosure policy page http_status: 200 - source: https://bugcrowd.com/devtools-vdp kind: bug bounty / VDP program http_status: 200 - source: https://www.progress.com/trust-center kind: trust center (https://www.progress.com/security 301s here) http_status: 200