Boxabl Vulnerability Disclosure
BOXABL runs a real, publicly documented responsible-disclosure ("bug bounty") program. It is discoverable the correct way: an RFC 9116 security.txt at https://www.boxabl.com/.well-known/security.txt whose Contact field resolves to a published policy PDF. The policy defines scope, out-of-scope classes, rules of engagement, a safe-harbour clause, the submission channel and a discretionary CVSS-linked compensation model. This is notably more mature security-disclosure posture than most companies in the catalog that publish no API at all. Detail below was read from the policy PDF itself; the mechanical probe (0-working/probe-security-programs.py) independently confirmed the security.txt Contact hit.
Boxabl publishes a vulnerability disclosure policy for reporting security issues. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.