generated: '2026-09-19' method: searched probe: true source: well-known/smklog-com-security.txt url: https://smklog.com/.well-known/security.txt contact: - mailto:info@smklog.com policy: [] bug_bounty: false expires: '2027-07-29T00:00:00.000Z' preferred_languages: [en] canonical: https://smklog.com/.well-known/security.txt evidence: - source: well-known/smklog-com-security.txt kind: security.txt (RFC 9116, fetched live 2026-09-19, HTTP 200 text/plain) notes: - 'No Policy: field and no separate disclosure page (/security, /.well-known/security.txt on the API host and /security/responsible-disclosure all miss); the policy is the comment block in the file itself.' - 'Verbatim on money: "we do not run a bug bounty and we do not pay for vulnerability reports. That is not a negotiating position, it is the size of the company. Send the finding anyway if you have one; we fix what is real."' - 'Verbatim on scope: asks reporters to avoid load testing, denial of service and "anything that touches a real customer''s order or address data", and to describe rather than run a proof that would need customer data.' - 'No trust center or published certification programme was found (probe-security-programs.py: trust=none), so no TrustCenter or Compliance pointer is emitted.'