Sunbit · Vulnerability Disclosure

Sunbit Vulnerability Disclosure

Vulnerability disclosure

Sunbit runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

buy-now-pay-laterpoint-of-sale-financingconsumer-lendingpaymentsfintechcheckoutmerchant-onboardingwebhooksautomotivedentalveterinaryeyewearhealthcare-financingembedded-finance
Program: Hackerone security.txt present

Disclosure Policy

Security Contact

Contact
mailto:security@sunbit.com

Source

Vulnerability Disclosure

sunbit-vulnerability-disclosure.yml Raw ↑
generated: '2026-07-31'
method: searched
probe: true
source: https://sunbit.com/.well-known/security.txt
contact:
- mailto:security@sunbit.com
policy: []
encryption:
- https://sunbit.com/pgp-key.txt
preferred_languages:
- en
expires: '2022-12-31T21:59:00.000Z'
expired: true
security_txt:
  present: true
  url: https://sunbit.com/.well-known/security.txt
  http_status: 200
  content_type: text/plain
  file: well-known/sunbit-security.txt
  rfc9116_fields_present:
  - Contact
  - Expires
  - Encryption
  - Preferred-Languages
  rfc9116_fields_missing:
  - Policy
  - Acknowledgments
  - Canonical
  - Hiring
  signed: false
  note: >-
    Well-formed and reachable, but the Expires value is 2022-12-31 — more than three years
    stale as of this probe. RFC 9116 requires the file be refreshed before it expires, so a
    researcher following the spec should treat this contact as unmaintained.
bug_bounty:
  program: none found
  platforms_checked:
  - HackerOne
  - Bugcrowd
  - Intigriti
  result: no public program found
disclosure_pages_probed:
- url: https://sunbit.com/security/
  status: 404
- url: https://sunbit.com/responsible-disclosure/
  status: 404
- url: https://sunbit.com/vulnerability-disclosure/
  status: 404
- url: https://sunbit.com/compliance/
  status: 404
- url: https://security.sunbit.com/
  status: NXDOMAIN
- url: https://trust.sunbit.com/
  status: NXDOMAIN
evidence:
- source: https://sunbit.com/.well-known/security.txt
  kind: security.txt (live probe)
  fetched: '2026-07-31'
  http_status: 200
- source: https://sunbit.com/pgp-key.txt
  kind: encryption key referenced by security.txt
  fetched: '2026-07-31'
  http_status: 200
gaps:
- security.txt is expired (Expires 2022-12-31) and carries no Policy field, so there is a
  contact address but no published disclosure process or safe-harbour statement.
- No public bug bounty program on any major platform.
- No dedicated security, trust, or responsible-disclosure page anywhere on sunbit.com.