generated: '2026-08-26' method: searched source: https://www.satispay.com/.well-known/security.txt probe: true published: true mechanism: RFC 9116 security.txt contact: - mailto:security@satispay.com encryption_key: https://www.satispay.com/satispay-security.pub preferred_languages: - en expires: '2026-12-31T22:59:00.000Z' policy_url: null bug_bounty: program: false platforms_probed: - hackerone - bugcrowd - intigriti detail: No bug bounty or coordinated-disclosure program page was found on Satispay's own surface. evidence: - url: https://www.satispay.com/.well-known/security.txt http_status: 200 file: well-known/satispay-security.txt kind: RFC 9116 security.txt - url: https://www.satispay.com/satispay-security.pub http_status: 200 kind: PGP encryption key referenced by the Encryption field - url: https://developers.satispay.com/.well-known/security.txt http_status: 404 kind: absent on the developer portal host - url: https://authservices.satispay.com/.well-known/security.txt http_status: 404 kind: absent on the API host gaps: - >- No Policy field, so security.txt names a contact but links no disclosure policy, no scope statement and no safe-harbour language — a researcher has an inbox but no rules. - >- Served only on www.satispay.com. A researcher who finds the developer portal or the API host first gets a 404, and RFC 9116 expects the file on the host in question. - No Canonical and no Acknowledgments field.