generated: '2026-09-01' method: searched probe: true source: well-known/0xarchive-security.txt contact: - mailto:support@0xarchive.io evidence: - source: well-known/0xarchive-security.txt kind: security.txt (previously harvested) policy_published: false bug_bounty: false bug_bounty_probe: checked: '2026-09-01' method: 0-working/probe-security-programs.py, which scans the security.txt and the site for HackerOne, Bugcrowd, Intigriti and disclosure-page markers result: >- No bug-bounty or disclosure program found. The security.txt carries no Policy line and no bounty-platform URL, and the probe found no trust center or named certification. security_txt: url: https://0xarchive.io/.well-known/security.txt http_status: 200 content_type: text/plain fetched: '2026-09-01' fields_present: - Contact - Expires - Preferred-Languages - Canonical fields_absent: - Policy - Encryption - Acknowledgments - Hiring - CSAF expires: '2027-08-30' expires_valid: true note: >- RFC 9116 compliant and, importantly, NOT expired - the Expires field runs to 2027-08-30, which is nearly a year out. A large share of published security.txt files in this catalog are stale; this one is current. What it lacks is a Policy field: there is a monitored contact but no stated disclosure policy, so a researcher knows who to tell and not what to expect back. recommendation: >- Adding a single Policy: line pointing at a short disclosure page would complete this file at essentially zero cost, and it is the only thing standing between this and a full vulnerability disclosure posture.