generated: '2026-08-26' method: searched probe: true source: https://regscale.com/security/ note: >- RegScale runs a vulnerability reporting channel but not a public bug bounty. The security page carries a "Report a Security Vulnerability" section with an intake form - "If you have found a security issue or vulnerability in the RegScale platform and would like to report it to us, please fill out the following form to report it to our team" - and names a Director of Information Security. The automated probe (0-working/probe-security-programs.py) returned no hit because the disclosure text sits inside a JS-rendered WordPress section on a page it does not treat as a disclosure path; the finding here was read from the fetched page body directly. policy: - https://regscale.com/security/ contact: [] contact_note: >- No security@ address and no /.well-known/security.txt are published; the only stated channel is the web intake form on the security page. That is a real gap against RFC 9116 and is worth raising with the provider - a company whose product is continuous controls monitoring is an unusually good candidate for publishing a security.txt. bug_bounty: program: null platform: null note: no HackerOne, Bugcrowd or Intigriti program found security_txt: served: false probed: - url: https://regscale.com/.well-known/security.txt status: 404 - url: https://regscale.readme.io/.well-known/security.txt status: 404 evidence: - source: https://regscale.com/security/ kind: disclosure-page keywords: [report a security vulnerability, security issue, vulnerability] - source: https://regscale.com/security/ kind: named-security-officer detail: Dale Hoak, Director of Information Security, RegScale