generated: '2026-08-28' method: searched source: https://www.cantaloupe.com/legal/compliance/ provider: Seed providerId: seed-platform description: >- Cantaloupe publishes a named vulnerability-reporting route on its Data Security and Compliance page. There is no RFC 9116 security.txt, no bug-bounty program, and no published disclosure policy, SLA, or safe-harbour language. program: published: true type: security-contact page: https://www.cantaloupe.com/legal/compliance/ statement: >- "How can customers report security concerns or vulnerabilities to Cantaloupe? Customers can report security concerns or potential vulnerabilities by contacting our dedicated security team at [security email] or through our website's contact form. We take all reports seriously and investigate them promptly." contact_form: https://www.cantaloupe.com/contact/ email: null email_note: >- The page renders both its security-inquiry and vulnerability-reporting addresses through an email-obfuscation script, so the literal mailbox is not readable from the served HTML. Recorded as null rather than guessed. incident_response: >- The same page states Cantaloupe maintains an incident response plan covering containment, investigation, remediation, and notification of affected parties and regulatory bodies. bug_bounty: present: false platforms_checked: - hackerone - bugcrowd - intigriti note: No public bug-bounty or VDP platform listing was found. security_txt: present: false probed: - url: https://www.cantaloupe.com/.well-known/security.txt status: 404 - url: https://seedlive.com/.well-known/security.txt status: 404 - url: https://api.seedlive.com/.well-known/security.txt status: 403 x-evidence: fetched: '2026-08-28' url: https://www.cantaloupe.com/legal/compliance/ http_status: 200 content_type: text/html