generated: '2026-08-09' method: searched probe: true source: https://wealthville.net/security policy: - https://wealthville.net/security contact: - support@wealthville.net bug_bounty: paid: false note: No paid bounty. The provider offers public attribution for valid reports on request. policy_summary: >- Report privately first and allow time to fix before public disclosure; include reproducible steps and an impact assessment. The provider commits to acknowledgement and status updates. audits: third_party: false internal_review: date: '2026-05' scope: perpetual and swap integrations findings: 8 critical/high severity, remediated before deployment provider_statement: >- "An internal review is not a substitute for an external one, and we are not presenting it as one." security_txt: present: false probed: {url: "https://wealthville.net/.well-known/security.txt", http_status: 404} note: >- The disclosure policy is real but human-only. Publishing RFC 9116 security.txt at /.well-known/security.txt would make it machine-discoverable at zero cost. evidence: - {source: https://wealthville.net/security, http_status: 200, kind: disclosure page, keywords: [vulnerability, responsible disclosure, report it privately]}