generated: '2026-09-19' method: searched probe: true source: well-known/relmcrm-com-security.txt (https://relmcrm.com/.well-known/security.txt, 200) + https://relmcrm.com/security (Responsible disclosure) + https://relmcrm.com/support summary: >- A real but minimal disclosure channel: an RFC 9116 security.txt with a Contact, an Expires and a Canonical field (no Policy, no Encryption, no Acknowledgments), and a "Responsible disclosure" section on the security page that asks for reports by email and promises to "acknowledge and work with you in good faith". No bug bounty (not on HackerOne, Bugcrowd or Intigriti), no published response timeline, no safe-harbour statement, no PGP key. contact: - mailto:security@relmcrm.com security_txt: file: well-known/relmcrm-com-security.txt url: https://relmcrm.com/.well-known/security.txt fields: Contact: mailto:security@relmcrm.com Expires: '2026-12-31T23:59:59.000Z' Preferred-Languages: en Canonical: https://relmcrm.com/.well-known/security.txt missing_fields: [Policy, Encryption, Acknowledgments, Hiring] valid: true expires_in_days_from_check: 103 disclosure_page: url: https://relmcrm.com/security section: Responsible disclosure quote: '"Found a vulnerability? Please report it to security@relmcrm.com. See /.well-known/security.txt. We will acknowledge and work with you in good faith."' http_status: 200 fetched: '2026-09-19' bug_bounty: program: none platforms_checked: [HackerOne, Bugcrowd, Intigriti] response_commitment: none stated for security reports (general support aims for one business day — https://relmcrm.com/support) safe_harbor: not stated posture_statement: '"We are deliberate about the security basics above, and we are not going to claim certifications we do not yet hold (no SOC 2 badge theatre)." — https://relmcrm.com/security. No trust center and no certifications are published; no TrustCenter or Compliance pointer is emitted.' evidence: - source: well-known/relmcrm-com-security.txt kind: security.txt (harvested this pass, HTTP 200) - source: https://relmcrm.com/security kind: responsible-disclosure section (HTTP 200)