generated: '2026-08-11' method: probed source: live probes of tadeus.net, www.tadeus.net and app.tadeus.net present: false policy_url: null security_contact: null bug_bounty: present: false platforms_checked: [HackerOne, Bugcrowd, Intigriti] found: [] note: >- Tadeus publishes no vulnerability disclosure policy, no security contact address and no bug bounty. /.well-known/security.txt returns 403 on every host — the whole /.well-known/ prefix is blocked at the edge. There is no /security page (404), no security email on the contact page (which is a form only, with no address), and no email address on the privacy policy. NO `Security` pointer is emitted in apis.yml, because there is nothing to point at. This is a recorded absence. x-evidence: fetched: '2026-08-11' evidence: - url: https://tadeus.net/.well-known/security.txt http_status: 403 - url: https://app.tadeus.net/.well-known/security.txt http_status: 403 - url: https://www.tadeus.net/.well-known/security.txt http_status: 403 - url: https://tadeus.net/security http_status: 404 - url: https://tadeus.net/contact http_status: 200 note: contact form only; no security address published provider_gap: >- Publish an RFC 9116 /.well-known/security.txt with a Contact and a Policy field, and a short disclosure policy page. This is a few hours of work and it is currently the largest unforced gap in a security posture that is otherwise marketed heavily.