generated: '2026-09-05' method: searched source: https://zenledger.io/security/ program: exists: true type: bug-bounty name: ZenLedger Bounty Program platform: self-hosted third_party_platform: null policy_url: https://zenledger.io/security/ submission_url: https://share.hsforms.com/1fwWv4cphQHaX8Bha50Kqwgdchb2 submission_channel: HubSpot form linked from the security page as "Security Bounty Form" security_contact_email: security@zenledger.io contact_note: >- The security page states "if you wish to report a potential security issue, please contact" followed by an obfuscated mailto that renders as "[email protected]" in the static HTML. The address is not readable from the served markup, so the form is the only unambiguous reporting channel. rewards: paid: true amounts_published: false detail: >- "We review vulnerability feedback from contributors that cite security issues in detail and provide competitive bounties for included fixes. Please note we have controls in place so each submission for bounty is reviewed and assessed bounty worthy status or none. Feedback is only given on bounty awards." scope_published: false safe_harbor_published: false response_sla_published: false disclosure_policy_published: false routing_note: >- The page explicitly separates security reports from consumer support — "If you are a consumer with an issue, please reach out to our customer support via chat or email." security_txt: served: false probed: - url: https://zenledger.io/.well-known/security.txt status: 404 - url: https://api.zenledger.io/.well-known/security.txt status: 404 - url: https://docs.zenledger.io/.well-known/security.txt status: 200 result: html-shell note: Static-site catch-all returning the same 14,019-byte HTML page for every path; not a security.txt. gap: >- ZenLedger runs a real bounty program but publishes no RFC 9116 security.txt on any host, so an automated scanner or an agent has no machine-readable route to the program. This is the single cheapest fix available on this record. incident_response: documented: true evidence: >- "We have a process for handling information security events which includes escalation procedures, rapid mitigation and communication." — https://zenledger.io/security/ public_postmortems: false status_page: https://status.zenledger.io/