generated: '2026-08-26' method: probed source: live probes of Revinate hosts, 2026-08-26 present: false policy_url: null security_contact: null bug_bounty: present: false platform: null note: >- No vulnerability disclosure program was found. Revinate serves no /.well-known/security.txt on any host, publishes no /security/ page, and no Revinate program is visible on HackerOne, Bugcrowd or Intigriti. A researcher who finds a flaw in the Porter API has no published, dedicated channel and would have to route it through general support. Recorded as an absence with the probes behind it; deliberately NOT wired as a `Security` pointer, since that would assert a disclosure surface Revinate does not serve. evidence: - url: https://www.revinate.com/.well-known/security.txt status: 404 note: Returns the WordPress themed 404 page. - url: https://auth.revinate.com/.well-known/security.txt status: 404 note: 'Returns plain text "Not found."' - url: https://porter.revinate.com/.well-known/security.txt status: 401 note: API host requires authentication for every path; no anonymous security.txt. - url: https://www.revinate.com/security/ status: 404 note: Page not found. recommendation: >- For the provider — publishing an RFC 9116 /.well-known/security.txt with a Contact and Policy field is a low-cost, high-signal fix, and would pair naturally with the existing Trust Center.