generated: '2026-09-02' method: searched probe: true source: https://validusgrp.com/assets/vulnerability-disclosure-policy.pdf policy: https://validusgrp.com/assets/vulnerability-disclosure-policy.pdf security_txt: https://validusgrp.com/.well-known/security.txt contact: - mailto:security@validus.sg bug_bounty: null note: >- Validus Group publishes a named Vulnerability Disclosure Policy, linked from the footer of every page on validusgrp.com and served as a PDF (HTTP 200, application/pdf, 137 KB). It also serves an RFC 9116 /.well-known/security.txt on validusgrp.com and validus.vn naming mailto:security@validus.sg as the contact. Two gaps worth reporting back to the provider: the security.txt Expires field reads 2026-02-18T09:31:00Z and is therefore stale, and the security.txt carries no Policy: line pointing at the disclosure PDF that the company already publishes, so a machine reading the security.txt cannot find the policy. No public bug bounty program (HackerOne / Bugcrowd / Intigriti) was found. evidence: - source: https://validusgrp.com/.well-known/security.txt kind: security.txt (live probe) http_status: 200 content_type: text/plain; charset=utf-8 - source: https://validus.vn/.well-known/security.txt kind: security.txt (live probe, byte-identical) http_status: 200 - source: https://validusgrp.com/assets/vulnerability-disclosure-policy.pdf kind: published vulnerability disclosure policy (PDF) http_status: 200 content_type: application/pdf