generated: '2026-08-29' method: searched source: https://portal.tcs.taranawireless.com/.well-known/security.txt name: Tarana Wireless — vulnerability disclosure published: true security_txt: url: https://portal.tcs.taranawireless.com/.well-known/security.txt status: 200 artifact: well-known/tarana-wireless-security.txt rfc: RFC 9116 contact: - mailto:tcs-security@taranawireless.com hiring: https://taranawireless.applytojob.com preferred_languages: - en policy_url: null encryption_key: null acknowledgments_url: null canonical: null expires: null bug_bounty: program: false platforms_checked: - HackerOne - Bugcrowd - Intigriti result: no program found note: >- A real, served RFC 9116 security.txt with a dedicated product-security mailbox — notable because it is published on the TCS operator portal host (where the product lives) rather than on the marketing site, which is the host that actually matters for a reporter. What it lacks is the rest of the file: no Policy URL, so a reporter has no stated disclosure terms, safe-harbour language or expected response time; no Expires field, which RFC 9116 marks REQUIRED; and no Encryption, Acknowledgments or Canonical field. The gap is cheap to close and is the single highest-value security-posture fix available to Tarana. evidence: - url: https://portal.tcs.taranawireless.com/.well-known/security.txt status: 200 content_type: text/plain - url: https://www.taranawireless.com/.well-known/security.txt status: 403 note: Cloudflare/Kinsta bot policy on the marketing host; no security.txt served there. - url: https://support.taranawireless.com/.well-known/security.txt status: 401