generated: '2026-08-14' method: searched probe: true source: https://www.revv.so/trust/security.html policy: [] contact: - security@revvsales.com bug_bounty: null security_txt: false note: >- Revv publishes a security contact but no disclosure programme. The only channel found is a mailto:security@revvsales.com link on the Trust Center page (note the address is on the legacy revvsales.com domain, the pre-rename company name). There is no responsible-disclosure or vulnerability-disclosure policy page, no safe-harbour statement, no bug bounty (HackerOne / Bugcrowd / Intigriti all absent), and no /.well-known/security.txt on any Revv host — www.revv.so returns 404 for it and the product subdomains answer 200 with a LegalZoom SPA shell, which is not a document. No `Security` pointer is emitted: a contact address alone is not a published disclosure policy. evidence: - source: https://www.revv.so/trust/security.html kind: security-contact detail: mailto:security@revvsales.com in the Trust Center page markup status: 200 - source: https://www.revv.so/.well-known/security.txt kind: security.txt detail: not served status: 404 x-evidence: - url: https://www.revv.so/trust/security.html status: 200 fetched: '2026-08-14' - url: https://www.revv.so/.well-known/security.txt status: 404 fetched: '2026-08-14'