generated: '2026-09-06' method: probed probe: true source: https://dash.aclid.bio/.well-known/security.txt note: >- probe-security-programs.py returned vdp=none because it probes the registrable domain and the OpenAPI hosts; Aclid serves its RFC 9116 document on the two application hosts instead (dash.aclid.bio and verify.aclid.bio), which are named as components on its status page. Fetched by hand 2026-09-06. policy: [] contact: - mailto:contact@aclid.bio - https://aclid.bio/contact expires: '2026-04-07T00:00:00Z' expired: true grade: thin grade_reason: >- A served, correctly-typed security.txt is more than most companies this size publish, but this one is expired (Expires 2026-04-07, five months before this probe), has no Policy field, no Encryption key, no Preferred-Languages and no Canonical, and routes reporters to the general company contact address rather than a security alias. RFC 9116 says an expired file must not be relied upon. bug_bounty: null bug_bounty_note: No HackerOne, Bugcrowd or Intigriti program found. disclosure_page: null disclosure_page_note: 'Probed 2026-09-06: https://www.aclid.bio/security -> 404, /responsible-disclosure -> 404 (site is a Webflow marketing site with no security section).' evidence: - {source: 'https://dash.aclid.bio/.well-known/security.txt', kind: security.txt, http_status: 200, content_type: 'text/plain; charset=utf-8', bytes: 99, fetched: '2026-09-06'} - {source: 'https://verify.aclid.bio/.well-known/security.txt', kind: security.txt, http_status: 200, content_type: 'text/plain; charset=utf-8', bytes: 99, fetched: '2026-09-06', note: byte-identical to the dash copy} - {source: 'https://www.aclid.bio/.well-known/security.txt', kind: security.txt, http_status: 404, fetched: '2026-09-06'} - {source: 'https://api.aclid.bio/.well-known/security.txt', kind: security.txt, http_status: 404, fetched: '2026-09-06'} file: well-known/aclid-security.txt