generated: '2026-08-11' method: searched probe: true source: https://proofdraw.com/contact policy: [] policy_url: https://proofdraw.com/contact contact: - security@proofdraw.com commitments: acknowledgement: within 48 hours credit: >- "We credit reporters who follow standard disclosure timelines." No named timeline, no safe-harbour language, and no scope statement are published. bug_bounty: program: none platforms_checked: [HackerOne, Bugcrowd, Intigriti] found: false evidence: - source: https://proofdraw.com/contact status: 200 kind: disclosure-contact quote: >- "Security — security@proofdraw.com — Responsible disclosure. We acknowledge within 48 hours and credit reporters who follow standard disclosure timelines." note: >- Published on the Contact section of the ProofDraw site as one of three named inboxes (general, press, security). The address is Cloudflare email-protected in the markup and decodes to security@proofdraw.com. - source: https://proofdraw.com/.well-known/security.txt status: 404 kind: security.txt note: >- No RFC 9116 security.txt is served. A researcher scanning the machine-readable path finds nothing; the channel is discoverable only by reading the Contact page. - source: https://proofdraw.com/security status: 404 kind: disclosure-page note: No dedicated /security or /responsible-disclosure page exists. gaps: - No /.well-known/security.txt — the contact is human-discoverable only. - No published scope, safe-harbour, or coordinated-disclosure timeline. - No PGP key, no encrypted-report channel, no acknowledgements/hall-of-fame page.