generated: '2026-09-05' method: searched source: https://www.carmax.com/.well-known/security.txt (archived 2026-02-03, status 200) + https://www.carmax.com/responsible-disclosure provider: CarMax providerId: carmax program: exists: true type: responsible-disclosure name: CarMax Responsible Disclosure for Security Vulnerabilities policy_url: https://www.carmax.com/responsible-disclosure contact: mailto:responsible_disclosure@carmax.com bug_bounty: false bounty_platform: null preferred_languages: en hiring: https://careers.carmax.com/us/en/search-results?keywords=cybersecurity security_txt: served: true path: /.well-known/security.txt file: ../well-known/carmax-security.txt live_status: 403 archived_status: 200 archived_url: https://web.archive.org/web/20260203040122id_/https://www.carmax.com/.well-known/security.txt fields: Contact: mailto:responsible_disclosure@carmax.com Expires: '2024-12-31T05:00:00.000Z' Preferred-Languages: en Hiring: https://careers.carmax.com/us/en/search-results?keywords=cybersecurity rfc9116_issues: - id: expired detail: >- The "Expires" field is 2024-12-31T05:00:00.000Z. Under RFC 9116 a security.txt past its Expires value should not be relied on; CarMax has not refreshed it. - id: no-policy-field detail: >- No "Policy" field, although CarMax does publish a policy page at /responsible-disclosure. Adding "Policy: https://www.carmax.com/responsible-disclosure" would make the two documents point at each other. - id: no-canonical-field detail: No "Canonical" field. evidence: - url: https://www.carmax.com/.well-known/security.txt status: 403 note: live probe 2026-09-05 — Akamai bot-manager refusal, not absence - url: https://web.archive.org/web/20260203040122id_/https://www.carmax.com/.well-known/security.txt status: 200 note: verbatim RFC 9116 body, saved to well-known/carmax-security.txt - url: https://www.carmax.com/responsible-disclosure status: 403 note: live probe 2026-09-05 refused; Wayback capture 2026-08-22 returns status 200 with the title "CarMax Responsible Disclosure for Security Vulnerabilities" and a "Report vulnerability" action. The page body is client-rendered, so the archived HTML carries the title only. notes: >- CarMax runs a coordinated vulnerability-disclosure program with a dedicated intake address and a published policy page. There is no paid bug bounty and no HackerOne, Bugcrowd or Intigriti listing was found. The one gap worth reporting back to CarMax is the expired security.txt. maintainers: - FN: Kin Lane email: kin@apievangelist.com