generated: '2026-09-04' method: probed probe: true source: live probes 2026-09-04 found: false policy: [] contact: [] bug_bounty: null note: >- NO vulnerability disclosure programme was found. /.well-known/security.txt returns 404 on workspot.com, www.workspot.com and docs.workspot.com (and 403 from the api.workspot.com gateway, which rejects every unauthenticated path including nonexistent ones). https://www.workspot.com/security/ returns 404. The public Trust Center describes an annual external audit and a Bitsight security rating but names no disclosure channel, no security@ address and no bug bounty on HackerOne, Bugcrowd or Intigriti. The only published security-adjacent contact is privacy@workspot.com, which is a privacy contact, not a vulnerability intake. Consequence: a researcher who finds a flaw in Workspot has no published route to report it. No `Security` pointer is emitted in apis.yml, because there is no disclosure page to point at. evidence: - {url: 'https://www.workspot.com/.well-known/security.txt', status: 404} - {url: 'https://workspot.com/.well-known/security.txt', status: 404} - {url: 'https://docs.workspot.com/.well-known/security.txt', status: 404} - {url: 'https://www.workspot.com/security/', status: 404} - {url: 'https://www.workspot.com/resources/trust-center/', status: 200, note: no disclosure channel named}