generated: '2026-08-26' method: probed source: https://www.quaise.com/.well-known/security.txt summary: >- Quaise Energy serves an RFC 9116 security.txt at the canonical well-known path, but the file is an UNEDITED TEMPLATE and the disclosure program it describes does not exist. The required Contact field is the literal placeholder "user@example.com", and all three optional URLs it advertises return 404. There is no reachable way to report a vulnerability through this channel. program_status: non-functional served: true http_status: 200 fields: contact: - value: user@example.com valid: false note: >- RFC 9116 requires Contact. This is the unedited placeholder shipped by the generator (the site runs Craft CMS/SEOmatic), not a real reporting address. A researcher following it reaches nobody. expiration: value: '2026-08-26T04:02:08-07:00' valid: false note: >- The Expires timestamp is same-day as the probe, indicating the value is generated dynamically on each request rather than maintained. RFC 9116 says an expired file must not be trusted. encryption: value: https://www.quaise.com/pgp-key.txt http_status: 404 valid: false policy: value: https://www.quaise.com/security-policy http_status: 404 valid: false acknowledgements: value: https://www.quaise.com/hall-of-fame http_status: 404 valid: false bug_bounty: none alternate_contacts: - value: press@quaise.com source: https://www.quaise.com/company note: Press address published on the company page; not a security contact. evidence: - url: https://www.quaise.com/.well-known/security.txt status: 200 note: Served, real RFC 9116 text document (528 bytes), not an HTML shell. - url: https://www.quaise.com/security-policy status: 404 - url: https://www.quaise.com/pgp-key.txt status: 404 - url: https://www.quaise.com/hall-of-fame status: 404 remediation: >- Replace the placeholder Contact with a monitored security address (or a report form URL), and either publish the advertised /security-policy, /pgp-key.txt and /hall-of-fame pages or remove those lines. A security.txt pointing at three 404s and user@example.com is worse than none — it advertises a reporting channel that silently drops reports. note: >- No `Security` pointer is emitted in apis.yml for this artifact. The security_disclosure check asserts the provider operates a disclosure channel; this one is served but non-functional, so claiming it would be a false credit.