generated: '2026-08-29' method: probed source: https://www.sygnum.com/.well-known/security.txt http_status: 200 program: security_txt: true policy_url: null bug_bounty: false platform: null contact: - mailto:security@sygnum.com document: well-known/sygnum-security.txt content: | # Our security address Contact: mailto:security@sygnum.com note: >- Sygnum serves a valid RFC 9116 security.txt with a security contact address. It carries a Contact field only — no Policy, Encryption, Preferred-Languages, Canonical or Expires field — so there is a reporting channel but no published disclosure policy, safe-harbour statement or bug-bounty programme. Searches of www.sygnum.com and the major bounty platforms (HackerOne, Bugcrowd, Intigriti) found no Sygnum programme. caveat: >- www.sygnum.com sits behind a Cloudflare bot challenge that answers 403 to browser-style User-Agents; the file is served normally to a plain probe User-Agent, which is how it was read and verified twice (www.sygnum.com and sygnum.com, both HTTP 200, 58 bytes). evidence: - url: https://www.sygnum.com/.well-known/security.txt status: 200 - url: https://sygnum.com/.well-known/security.txt status: 200