generated: '2026-09-05' method: probed source: https://www.aavantgarde.com/.well-known/security.txt http_status: 200 program: none note: >- AAVantgarde Bio serves a security.txt but does NOT operate a vulnerability disclosure program in any meaningful sense, and this artifact records that distinction rather than crediting the file's mere presence. The document carries only Contact and Expires. There is no Policy field, so no disclosure terms are published anywhere. The Expires value is 2026-01-01T23:59:00.000Z, which was already in the past when probed on 2026-09-05 — RFC 9116 section 2.5.5 says an expired file must not be used. The Contact address (webservices@sampsonmay.com) belongs to Sampson May, the agency that built the corporate website, not to an AAVantgarde security function. Searches found no HackerOne, Bugcrowd or Intigriti program and no /security, /responsible-disclosure or /trust page on aavantgarde.com. For those reasons NO canonical `Security` pointer is emitted in apis.yml: the check it feeds asserts a published disclosure policy, and this company has not published one. contact: - mailto:webservices@sampsonmay.com policy_url: null expires: '2026-01-01T23:59:00.000Z' expired: true bug_bounty: null evidence: - source: https://www.aavantgarde.com/.well-known/security.txt status: 200 kind: security.txt (RFC 9116), fetched verbatim to well-known/aavantgardebio-security.txt - source: https://www.aavantgarde.com/.well-known/security.txt status: 200 kind: no Policy field present