generated: '2026-09-19' method: searched source: https://github.com/wangletiand/gpt55-x402-gateway/blob/main/SECURITY.md corroboration: - https://raw.githubusercontent.com/wangletiand/gpt55-x402-gateway/main/SECURITY.md # 200, 838 B, saved as 558686-xyz-SECURITY.md - https://github.com/wangletiand/gpt55-x402-gateway/blob/main/README.md # "Support and Security: For security reports, follow SECURITY.md" - https://gpt55.558686.xyz/.well-known/security.txt # 404 - https://gpt55.558686.xyz/security # 404 - https://gpt55.558686.xyz/privacy # 200 - "Wallet boundary" section repeats the never-share-keys rule checked: '2026-09-19' summary: >- The provider publishes a vulnerability disclosure policy as a SECURITY.md in its public repository: report privately by email to ops@400860.xyz, never in a public issue, with the minimum sanitized reproduction (route, method, response status, impact) and every secret and wallet signature redacted. Scope is the default branch and the live service https://gpt55.558686.xyz. There is no RFC 9116 security.txt on any host, no bug bounty, no PGP key, no acknowledgement or fix timeline, and no safe-harbour language. The repository has issues disabled, so email is the only channel. The contact domain (400860.xyz) is the sibling record in this catalog and also hosts the Sub2API recharge shop, which is how the two records are known to share an operator. policy: url: https://github.com/wangletiand/gpt55-x402-gateway/blob/main/SECURITY.md raw: https://raw.githubusercontent.com/wangletiand/gpt55-x402-gateway/main/SECURITY.md file: 558686-xyz-SECURITY.md contact: mailto:ops@400860.xyz reporting_verbatim: >- Report security issues privately by email to `ops@400860.xyz`. Do not open a public issue containing credentials, private keys, seed phrases, payment headers, API keys, personal data, or unredacted payment evidence. scope_verbatim: >- Security updates apply to the default branch of this repository and the live service at `https://gpt55.558686.xyz`. wallet_boundary_verbatim: >- The service never needs a buyer's private key. Any optional real-payment mode in this repository runs locally in the buyer-controlled Node.js process. The default mode is quote-only and does not sign or broadcast a transaction. response_sla: not-stated safe_harbour: not-stated pgp_key: none bug_bounty: none platforms: [] security_txt: served: false probed: ['https://gpt55.558686.xyz/.well-known/security.txt -> 404', 'https://sub2api.558686.xyz/.well-known/security.txt -> 200 SPA shell (not a document)', 'https://x402-*.558686.xyz/.well-known/security.txt -> 410'] sub2api: note: 'No security policy, contact or security.txt on sub2api.558686.xyz or api.558686.xyz; the Sub2API docs advise revoking a leaked key immediately in the console.'