generated: '2026-08-13' method: searched probe: true source: https://trust.confirm.com/ note: >- WorkRamp ships no /.well-known/security.txt on any host (all probes 404 — see well-known/workramp-well-known.yml). The disclosure surface lives on the Confirm trust center instead, because WorkRamp is now Confirm's "Learn:Up" / "Academy" product line and www.workramp.com 301s to www.confirm.com. policy: - https://trust.confirm.com/ - https://www.confirm.com/policies/security contact: - security@confirm.com program: type: responsible-disclosure bug_bounty: false platform: null reward: none published intake: >- "If you think you may have discovered a vulnerability, please send us a note" — Report issue form on the SafeBase trust center, plus the security@confirm.com address published on the same page. security_txt: false supporting_controls: - Responsible Disclosure (App Security section of the trust center) - Code Analysis - Credential Management - Annual third-party penetration testing; pentest report available under NDA evidence: - source: https://trust.confirm.com/ kind: trust-center http_status: 200 detail: 'App Security > Responsible Disclosure; "Report issue" intake; security@confirm.com published on page' - source: https://www.confirm.com/policies/security kind: security-policy-page http_status: 200 detail: annual third-party penetration testing, TLS 1.2+, ISO27001:2022 cert 188806 - source: https://app.workramp.com/.well-known/security.txt kind: security.txt http_status: 404 detail: no RFC 9116 file served on the API host