generated: '2026-08-31' method: searched probe: true source: https://tvarka.pro/saugumas/ policy: - https://tvarka.pro/saugumas/ contact: - https://tvarka.pro/kontaktai/ - info@tvarka.pro security_txt: true security_txt_file: well-known/tvarka-security.txt security_txt_url: https://tvarka.pro/.well-known/security.txt bug_bounty: false program: kind: informal-invitation statement_lt: >- "Pastebejote spraga? Jei radote saugumo problema ar turite klausimu apie duomenu apsauga, susisiekite - i saugumo pranesimus reaguojame pirmiausia." statement_en: >- "Spotted a vulnerability? If you found a security problem or have questions about data protection, get in touch - we respond to security reports first." note: >- A published, explicit invitation to report vulnerabilities on the provider's security page, with a stated response priority, NOW BACKED BY A MACHINE-READABLE RFC 9116 security.txt at https://tvarka.pro/.well-known/security.txt (200 on 2026-08-31; the same path 404d on 2026-08-09). The security.txt names the same policy page and the same general mailbox. There is still no dedicated security@ address, no named response SLA and no bug-bounty program (no HackerOne / Bugcrowd / Intigriti presence found). security_txt_fields: Contact: mailto:info@tvarka.pro Expires: '2027-08-30T00:00:00Z' Preferred-Languages: lt, en Canonical: https://tvarka.pro/.well-known/security.txt Policy: https://tvarka.pro/saugumas/ note: >- Five fields, all valid, with a non-expired Expires. It is served only on the apex - the API hosts atk.tvarka.pro and sign-api.tvarka.pro both still 404 - which is acceptable under RFC 9116 for a single organisation but means a scanner pointed at the API host alone will miss it. closed_since_previous_probe: - RFC 9116 security.txt is now published (was the top gap on 2026-08-09). gaps: - No security.txt on the API hosts themselves, only on the apex domain. - No dedicated security contact address; reports go to the general info@ mailbox. - No published disclosure timeline or safe-harbour statement. - No Encryption or Acknowledgments field in the security.txt. - No bug-bounty or coordinated-disclosure program. evidence: - {source: 'https://tvarka.pro/saugumas/', http_status: 200, kind: security-page, keywords: [saugumo problema, saugumo pranesimus, BDAR, eIDAS, QTSP, TLS]} - {source: 'https://tvarka.pro/kontaktai/', http_status: 200, kind: contact-page} - {source: 'https://atk.tvarka.pro/.well-known/security.txt', http_status: 404, kind: security.txt} - {source: 'https://tvarka.pro/.well-known/security.txt', http_status: 200, kind: security.txt, probed: '2026-08-31', note: 'was 404 on 2026-08-09'} - {source: 'https://sign-api.tvarka.pro/.well-known/security.txt', http_status: 404, kind: security.txt, probed: '2026-08-31'} - {source: 'https://atk.tvarka.pro/.well-known/security.txt', http_status: 404, kind: security.txt, probed: '2026-08-31'}