generated: '2026-09-04' method: probed source: DNS CAA record for widercircle.com (RFC 8659 iodef) + the public Incident Response Policy published at https://policy.widercircle.com/ program: none bug_bounty: false security_txt: false note: >- Wider Circle publishes NO /.well-known/security.txt and runs NO bug-bounty or coordinated-disclosure program on HackerOne, Bugcrowd or Intigriti. It does, however, publish a security reporting address in DNS: the widercircle.com CAA record carries an RFC 8659 iodef property naming security@widercircle.com. Its public policy site additionally documents an Incident Response Policy and a Breach Policy with named reporting channels and a stated 4-hour customer breach notification window. Those are the only published routes for reporting a security issue that a member of the public can find; there is no researcher-facing safe harbour, scope statement, or disclosure timeline. contacts: - address: security@widercircle.com channel: dns-caa-iodef evidence: 'dig CAA widercircle.com -> 0 iodef "mailto:security@widercircle.com"' verified: '2026-09-04' - address: privacy@widercircle.com channel: incident-response-policy evidence: https://policy.widercircle.com/ verified: '2026-09-04' policies: - name: Incident Response Policy url: https://policy.widercircle.com/ status: 200 note: Names the Security Incident Response Team (SIRT) and the identification / containment / eradication / recovery / follow-up phases, and lists the channels a workforce member or customer may use to report an incident. - name: Breach Policy url: https://policy.widercircle.com/ status: 200 note: 'States customer notification "no later than 4 hours after the discovery of the breach" and includes a sample customer notification letter.' - name: Vulnerability Scanning Policy url: https://policy.widercircle.com/ status: 200 - name: IDS Policy url: https://policy.widercircle.com/ status: 200 probes: - url: https://www.widercircle.com/.well-known/security.txt status: 404 - url: https://widercircle.com/.well-known/security.txt status: 404 - url: https://policy.widercircle.com/.well-known/security.txt status: 403 gaps: - No RFC 9116 security.txt at any host. - No public vulnerability disclosure policy addressed to external researchers. - No bug bounty or VDP platform listing found.