generated: '2026-08-02' method: probed source: live DNS/TLS/HTTP probes of apis.yml + OpenAPI hosts hosts: - host: www.arine.io https: true tls_version: TLSv1.3 cert_expires: Oct 7 01:22:20 2026 GMT hsts: true hsts_max_age: 31536000 - host: api.arine.io https: true tls_version: TLSv1.3 cert_expires: Oct 12 23:59:59 2026 GMT hsts: false note: AWS API Gateway; every probed path returns HTTP 403 ForbiddenException to anonymous callers - host: app.arine.io https: true tls_version: TLSv1.2 cert_expires: Oct 12 23:59:59 2026 GMT hsts: true hsts_max_age: 31536000 hsts_include_subdomains: true hsts_preload: true - host: docs.arine.io https: true tls_version: TLSv1.3 cert_expires: Sep 20 02:36:30 2026 GMT hsts: true hsts_max_age: 31536000 hsts_include_subdomains: true hsts_preload: true - host: blog.arine.io https: true tls_version: TLSv1.3 cert_expires: Oct 6 01:52:56 2026 GMT hsts: true hsts_max_age: 31536000 hsts_include_subdomains: true - host: go.arine.io https: true tls_version: TLSv1.3 cert_expires: Oct 7 14:34:31 2026 GMT hsts: true hsts_max_age: 31536000 domains: - domain: arine.io dnssec: true caa: [] spf: true dmarc: true dmarc_policy: quarantine findings: - No CAA records published for arine.io — any CA may issue for the domain. - DMARC policy is p=quarantine rather than p=reject. - No /.well-known/security.txt (RFC 9116) on any Arine host.