generated: '2026-09-17' method: searched probe: true source: https://www.ca.gov/.well-known/security.txt attribution: parent-domain attribution_note: >- Neither cppa.ca.gov (answers HTTP 300 Multiple Choices for every /.well-known/* path), privacy.ca.gov (404) nor api.drop.privacy.ca.gov (404) serves its own RFC 9116 security.txt. The document below is the State of California's statewide file on the registrable domain ca.gov (canonical https://www.ca.gov/.well-known/security.txt), whose Policy link is the California Department of Technology SIMM 5300 statewide information security policy that binds state agencies including the CPPA. Its Contact is the ca.gov web portal team, not an agency-specific security contact, so this is recorded as a parent-domain disclosure channel rather than a CPPA-published one; no `Security` pointer is emitted on that basis. policy: - https://cdt.ca.gov/policy/simm/#5300 contact: - mailto:cagov-website-info@state.ca.gov expires: '2026-12-31T23:59:00.000Z' canonical: https://www.ca.gov/.well-known/security.txt evidence: - source: https://ca.gov/.well-known/security.txt status: 301 redirect: https://www.ca.gov/.well-known/security.txt kind: security.txt (live probe) - source: https://www.ca.gov/.well-known/security.txt status: 200 kind: security.txt (live probe) - source: https://cppa.ca.gov/.well-known/security.txt status: 300 kind: Apache MultiViews "Multiple Choices" page, not a document - source: https://privacy.ca.gov/.well-known/security.txt status: 404 - source: https://api.drop.privacy.ca.gov/.well-known/security.txt status: 404