generated: '2026-09-01' method: searched source: https://www.uncountable.com/uncountable-security note: >- Uncountable serves no /.well-known/security.txt on any host (www 404, app 302 to /signin) and runs no public bug bounty program on HackerOne, Bugcrowd or Intigriti that could be found. What it does publish is a named security contact address and an annual external penetration testing commitment on its company security page. That is a disclosure channel, not a disclosure policy: no scope statement, safe-harbour language, response SLA or coordinated-disclosure timeline is published. program: bug_bounty: false platform: null security_txt: false security_txt_probes: - url: https://www.uncountable.com/.well-known/security.txt status: 404 - url: https://app.uncountable.com/.well-known/security.txt status: 302 - url: https://www.support.uncountable.com/.well-known/security.txt status: 301 contact: email: security@uncountable.com source: https://www.uncountable.com/uncountable-security page_status: 200 policy_url: null safe_harbor: null response_sla: null testing: external_penetration_testing: annual scope_claim: OWASP Top 10 and beyond vulnerability_scanning: regular network vulnerability scanning source: https://www.uncountable.com/uncountable-security