generated: '2026-08-27' method: searched probe: true source: >- https://www.blv.admin.ch/.well-known/security.txt (HTTP 200, fetched 2026-08-27, saved verbatim to well-known/swiss-food-composition-database-security.txt). www.blv.admin.ch is the Federal Food Safety and Veterinary Office - the publisher named on https://naehrwertdaten.ch/en/about/ - not the API host. Neither naehrwertdaten.ch nor api.webapp.prod.blv.foodcase-services.com serves a security.txt (both 404). program: Swiss Confederation Coordinated Vulnerability Disclosure (National Cyber Security Centre / BACS) policy: - https://www.bacs.admin.ch/en/framework-conditions-and-rules-cvd contact: - https://www.bacs.admin.ch/en/reporting-a-vulnerability - mailto:incidents@ncsc.ch encryption: https://www.bacs.admin.ch/en/contacts-ncsc#Encryption-keys preferred_languages: - en - de - fr - it expires: '2027-06-30T23:59:59Z' bug_bounty: present: true program: NCSC bug bounty programmes (federal government scope) url: https://www.bugbounty.ch/ncsc note: >- Named in the security.txt comment header as an opt-in programme for federal IT systems. The security.txt does not enumerate in-scope hosts, so it is not established here whether the Swiss Food Composition Database API host, which runs on the third-party FoodCASE platform, is inside that scope. evidence: - source: https://www.blv.admin.ch/.well-known/security.txt status: 200 kind: security.txt with Policy, Contact, Encryption and Expires fields - source: https://naehrwertdaten.ch/.well-known/security.txt status: 404 - source: https://api.webapp.prod.blv.foodcase-services.com/.well-known/security.txt status: 404