generated: '2026-08-29' method: probed source: >- Probes of https://stensul.com/.well-known/security.txt, https://stensul.com/security-trust-center/, https://trust.stensul.com/, and searches of HackerOne, Bugcrowd and Intigriti for a Stensul program, 2026-08-29. name: Stensul Vulnerability Disclosure found: false security_txt: url: https://stensul.com/.well-known/security.txt status: 404 note: >- Stensul's own apex serves no security.txt. Two subdomains DO serve one, but both belong to the hosting SaaS vendor, not to Stensul — status.stensul.com returns Atlassian's PGP-signed document (canonical www.atlassian.com, contact security@atlassian.com) and helpdesk.stensul.com returns Intercom's (canonical app.intercom.com, contact security@intercom.com, Bugcrowd disclosure terms). Neither routes a report to Stensul, so neither is counted here. disclosure_policy: found: false note: >- No responsible-disclosure or vulnerability-reporting page was found on stensul.com. The public security page (https://stensul.com/security-trust-center/) describes controls and the SOC 2 Type 2 audit but names no reporting channel or contact for security researchers. bug_bounty: found: false platforms_checked: - HackerOne - Bugcrowd - Intigriti note: No Stensul program surfaced on any of the three public platforms. recommendation: >- Publishing an RFC 9116 security.txt at https://stensul.com/.well-known/security.txt with a Contact and a Policy URL is the single cheapest fix available to Stensul here — a researcher who finds an issue today has no published route to report it. pointer_emitted: false pointer_note: >- No `Security` pointer is wired into apis.yml. The security_disclosure check asserts the provider publishes a disclosure channel, and Stensul does not.