generated: '2026-09-02' method: probed probe: true published: false policy: [] contact: [] summary: upGrad carries a HackerOne domain-verification TXT record on upgrad.com, which is placed to prove asset ownership for a HackerOne program - but no PUBLIC program, policy or disclosure page could be found, so the program appears to be private/invite-only. No security.txt is served. No Security or VulnerabilityDisclosure pointer is emitted, because neither a policy nor a contact is publicly readable. evidence: - source: dns:TXT upgrad.com kind: hackerone-domain-verification value: h1-domain-verification=sWWQhbwPcfAgdLtYwVPsjEF9XsS9rurxPF6KYkRWc1f8urV5 note: Real HackerOne asset-verification record - evidence a program relationship exists - source: https://hackerone.com/graphql kind: program-lookup http_status: 200 value: team(handle:"upgrad") -> NOT_FOUND "Team does not exist" note: No public HackerOne program page exists for this handle - source: https://hackerone.com/upgrad kind: page-probe http_status: 200 note: 200 is the HackerOne SPA shell; the control https://hackerone.com/not-a-real-program-zzz9981 returned 404, but /upgrad/policy_scopes returned 404 and the GraphQL team lookup is NOT_FOUND - not a published program - source: https://www.upgrad.com/.well-known/security.txt kind: security.txt http_status: 403 note: 403 AccessDenied from an S3 origin - no RFC 9116 document served remedy: Publish /.well-known/security.txt (RFC 9116) with a Contact and Policy URI, and a public responsible-disclosure page, so a researcher who finds something can route it without an invite.