generated: '2026-08-06' method: searched probe: true source: https://www.airtm.com/.well-known/security.txt contact: - mailto:orlando@150porciento.com evidence: - source: https://www.airtm.com/.well-known/security.txt kind: security.txt (live probe) expires: '2025-06-30T15:00:00Z' expired: true policy: [] security_txt_fields_present: [Contact, Expires] security_txt_fields_missing: [Policy, Encryption, Acknowledgments, Preferred-Languages, Canonical, Hiring] bug_bounty: program: null platforms_checked: [hackerone, bugcrowd, intigriti] found: false notes: >- Airtm serves an RFC 9116 security.txt at https://www.airtm.com/.well-known/security.txt (HTTP 200), but it is a two-line file whose own Expires date passed on 2025-06-30 — per RFC 9116 a researcher should treat the contents as stale. The single Contact is mailto:orlando@150porciento.com, a third-party (150 Porciento) rather than an @airtm.com security address, and there is no Policy URL, so a researcher has no published disclosure terms or safe-harbour statement. No bug bounty program was found on HackerOne, Bugcrowd or Intigriti. This is the clearest, cheapest fix on Airtm's operational-transparency surface: refresh the Expires date, add a Policy URL and an @airtm.com Contact.