generated: '2026-08-06' method: probed probe: true source: https://api.acrisure.com/.well-known/security.txt contact: - mailto:security@acrisure.com policy: [] policy_note: >- No Policy: field is published. The security.txt carries Contact, Expires, Canonical, Hiring and Preferred-Languages, but points at no disclosure policy, no safe-harbour statement and no bug bounty program. No Acrisure program was found on HackerOne, Bugcrowd or Intigriti, and https://www.acrisure.com/security and /trust both return 404. expires: '2027-01-16T12:00:00Z' expires_valid: true canonical: https://www.acrisure.com/.well-known/security.txt preferred_languages: en hiring: https://acrisure.wd1.myworkdayjobs.com/Acrisure served_on: - https://api.acrisure.com/.well-known/security.txt - https://www.acrisure.com/.well-known/security.txt - https://customer.acrisure.com/.well-known/security.txt served_on_note: >- The identical body is served from all three hosts, including the API host — better than most of the catalog, where security.txt is a marketing-host-only artifact. evidence: - source: well-known/acrisure-security.txt kind: security.txt (RFC 9116) url: https://api.acrisure.com/.well-known/security.txt http_status: 200 - source: probe kind: disclosure-page miss url: https://www.acrisure.com/security http_status: 404 - source: probe kind: trust-center miss url: https://trust.acrisure.com/ http_status: 403 x-evidence: fetched: '2026-08-06'