generated: '2026-08-13' method: searched source: >- https://trajectdata.com/vulnerability-reporting-policy/ (HTTP 200) and https://trajectdata.com/security-research-contributors (HTTP 200, reached via a 301 from https://trajectdata.com/security/) description: >- Traject Data — ValueSERP's operator — publishes a coordinated vulnerability disclosure policy on its corporate site, with a named security reporting address, an explicit safe-harbour commitment, defined out-of-scope testing rules and a public researcher acknowledgements page. It is NOT advertised at /.well-known/security.txt (that path returns 404 on every Traject Data host — see well-known/valueserp-well-known.yml), so the policy is discoverable by humans but not by machines. program: published: true scope: Traject Data (all products, including VALUE SERP) policy_url: https://trajectdata.com/vulnerability-reporting-policy/ acknowledgements_url: https://trajectdata.com/security-research-contributors contact: email: security@bytraject.com note: >- Published on the policy page behind Cloudflare email obfuscation; decoded from the page's data-cfemail attribute at fetch time. security_txt: false bug_bounty: false paid: false compensation_statement: >- "As a policy, Traject does not offer compensation for reported issues." The policy restates this: "We do not offer bug bounties or compensation for reported issues." safe_harbor: true safe_harbor_statement: >- Traject commits "not to initiate legal action against researchers for penetrating or attempting to penetrate our systems as long as they adhere to this policy." disclosure_model: coordinated / private disclosure to the vendor first testing_rules: allowed: - Testing against trial or beta instances and demo accounts. prohibited: - Any action that harms Traject or its users. - Unauthorized access to, or exfiltration of, customer or company data. - Destruction or corruption of data. - Physical or electronic attacks on Traject personnel, property or data centres. - Social engineering of Traject staff, contractors or customers. - Testing against live production accounts. response_commitments: - Acknowledge receipt of the report promptly. - Provide an estimated timeframe for resolution. - Notify the reporting researcher once the vulnerability is fixed. gaps: - >- No /.well-known/security.txt is served on trajectdata.com, valueserp.com or api.valueserp.com, so automated scanners and agents cannot discover this policy. Publishing an RFC 9116 security.txt naming https://trajectdata.com/vulnerability-reporting-policy/ as Policy and security@bytraject.com as Contact would close the gap with no change of substance. - No third-party bug bounty platform (HackerOne / Bugcrowd / Intigriti) listing was found.