generated: '2026-08-02' method: searched source: https://www.sayrhino.com/ probe: true summary: >- Rhino publishes a "Responsible disclosure" link in the site-wide footer of www.sayrhino.com pointing at a dedicated security mailbox. There is no /.well-known/security.txt (RFC 9116), no hosted disclosure policy page, and no public bug bounty program (HackerOne / Bugcrowd / Intigriti searches returned nothing for Rhino / SayRhino). The mailbox is the entire published surface. policy: [] contact: - mailto:security@sayrhino.com bug_bounty: null security_txt: null evidence: - source: https://www.sayrhino.com/ kind: footer-link label: Responsible disclosure href: mailto:security@sayrhino.com http_status: 200 - source: https://www.sayrhino.com/.well-known/security.txt kind: security.txt http_status: 404 present: false - source: https://api.prod.sayrhino.com/.well-known/security.txt kind: security.txt http_status: 404 present: false gaps: - No RFC 9116 security.txt on any host - No published disclosure policy page (scope, safe harbor, response SLA) - No public bug bounty or VDP platform listing x-evidence: fetched: '2026-08-02' url: https://www.sayrhino.com/ http_status: 200