generated: '2026-07-18' method: searched source: live probe of provider hosts hosts: - host: https://verify-api.arkoselabs.com documents: - path: /.well-known/security.txt status: 404 - path: /.well-known/openid-configuration status: 404 - path: /.well-known/oauth-authorization-server status: 404 - path: /.well-known/api-catalog status: 404 - host: https://www.arkoselabs.com documents: - path: /.well-known/security.txt status: 404 - path: /.well-known/ai-plugin.json status: 404 - host: https://developer.arkoselabs.com documents: - path: /.well-known/security.txt status: 404 notes: >- No /.well-known/ discovery documents are published on the API, marketing, or developer hosts. Absence recorded as valid data. Vulnerability disclosure runs through the HackerOne bug bounty program (see security/), not security.txt.