generated: '2026-08-29' method: searched source: https://www.stashaway.sg/security note: >- StashAway runs a public vulnerability disclosure programme on a dedicated host, but does NOT publish an RFC 9116 /.well-known/security.txt on any of its hosts, so the programme is invisible to any machine that looks for it at the standard location. The automated probe in probe-security-programs.py missed it for exactly that reason; it was found by reading the human-facing security page. Publishing a security.txt with `Policy: https://vdp.stashaway.com/` would make an already-existing programme machine-discoverable at zero cost. program: present: true name: StashAway Vulnerability Disclosure Policy url: https://vdp.stashaway.com/ hosted_on: vdp.stashaway.com (first-party subdomain, Quasar single-page app) platform: self-hosted (no HackerOne, Bugcrowd or Intigriti listing found) bug_bounty: unknown safe_harbor_stated: >- The public security page authorises reporting but states that "attempts to exploit" a vulnerability are prohibited. The full policy text is rendered client-side on vdp.stashaway.com and was not readable from the served HTML. security_txt: present: false probed: - url: https://www.stashaway.sg/.well-known/security.txt status: 404 - url: https://www.stashaway.my/.well-known/security.txt status: 404 - url: https://www.stashaway.ae/.well-known/security.txt status: 404 - url: https://www.stashaway.hk/.well-known/security.txt status: 404 evidence: - url: https://www.stashaway.sg/security status: 200 kind: disclosure pointer detail: >- Served HTML contains the literal string "vdp.stashaway.com/" three times, in the sentence "You can find more information on how to report here." - url: https://vdp.stashaway.com/ status: 200 kind: disclosure portal content_type: text/html; charset=utf-8 detail: >- Live host. The served body is a 2,087-byte single-page-app shell whose is "Vulnerability Disclosure Policy" and whose