generated: '2026-08-05' method: searched probe: true source: https://www.super.com/.well-known/security.txt name: Super.com vulnerability disclosure description: >- Super.com publishes an RFC 9116 security.txt at https://www.super.com/.well-known/security.txt naming a security contact and describing an invite-only Bugcrowd bug bounty program. There is no public program page: researchers are asked to email the contact first and are then invited in. security_txt: url: https://www.super.com/.well-known/security.txt status: 200 file: ../well-known/supercom-security.txt fields: contact: - mailto:security@super.com expires: '2030-01-01T08:24:00Z' hiring: https://landing.super.com/careers preferred_languages: EN policy: null encryption: null acknowledgments: null contact: - mailto:security@super.com bug_bounty: platform: Bugcrowd public_program_page: null access: invite-only intake: email security@super.com and request an invitation evidence: >- security.txt comment — "We have a BugCrowd program for security vulnerabilities: if you are reading this and have found a vulnerability, please email us and we can invite you to the program!" probed: - url: https://bugcrowd.com/super-com status: 404 - url: https://bugcrowd.com/engagements/super-com status: 404 - url: https://bugcrowd.com/snaptravel status: 404 policy_page: null evidence: - source: https://www.super.com/.well-known/security.txt status: 200 fetched: '2026-08-05' kind: RFC 9116 security.txt gaps: - >- No Policy: field in security.txt — no linked disclosure policy or safe-harbor statement. - >- No public Bugcrowd program page resolves; scope, rewards, and safe harbor are not publicly stated.