generated: '2026-08-13' method: probed probe: true source: live probe of SPOTIO's security.txt paths, disclosure pages and bug-bounty platforms published: false policy: [] contact: [] bug_bounty: none detail: >- SPOTIO publishes no vulnerability-disclosure programme. /.well-known/security.txt returns 404 on api.spotio2.com, app.spotio2.com, developer.spotio2.com and support.spotio.com, and 403 from the edge on spotio.com. The security and compliance page - which does describe SOC 2 Type II, GDPR, encryption, Azure hosting and Cloudflare WAF in detail - names no security contact address, no responsible-disclosure process and no bug-bounty programme. No SPOTIO programme was found on HackerOne, Bugcrowd or Intigriti. A researcher who found a flaw in SPOTIO today has no published route to report it other than general support. NO Security or VulnerabilityDisclosure pointer is emitted in apis.yml. This file records a verified absence, and an absence must not be scored as a presence. evidence: - {source: 'https://api.spotio2.com/.well-known/security.txt', status: 404} - {source: 'https://app.spotio2.com/.well-known/security.txt', status: 404} - {source: 'https://developer.spotio2.com/.well-known/security.txt', status: 404} - {source: 'https://support.spotio.com/.well-known/security.txt', status: 404} - {source: 'https://spotio.com/.well-known/security.txt', status: 403, note: edge blocks every /.well-known/* path} - {source: 'https://spotio.com/features/security-compliance/', status: 200, finding: 'no security contact, no disclosure policy, no bounty'} what_is_published_instead: url: https://spotio.com/features/security-compliance/ controls: - SOC 2 Type II across all five Trust Services Criteria, report available under NDA - GDPR commitment with EU data centres for residency - TLS 1.2+ in transit, enterprise-grade encryption at rest - Microsoft Azure hosting with multi-region redundancy - Cloudflare WAF and DDoS mitigation - role-based access control with automated audit logs artifact: security/spotio-trust-center.yml recommendation_for_provider: >- Publishing an RFC 9116 /.well-known/security.txt on spotio.com and api.spotio2.com with a Contact and Policy line would close this gap in an afternoon, and is the single cheapest security-posture improvement available to SPOTIO. checked: '2026-08-13'