generated: '2026-09-05' method: probed probe: true source: https://cleanshelf.com/.well-known/security.txt url: https://cleanshelf.com/.well-known/security.txt note: >- cleanshelf.com serves a real RFC 9116 security.txt (HTTP 200, text/plain, 85 bytes) that names SAP's vulnerability reporting page as the sole contact — the domain is operated by SAP through LeanIX, which acquired Cleanshelf in March 2021. A prior round of this record pointed at trust.zylo.com; that was a misattribution and the artifact has been removed. contact: - https://www.sap.com/report-a-vulnerability expires: '2026-01-30T18:29:00.000Z' expired: true expired_note: >- The Expires field is in the past as of 2026-09-05, so under RFC 9116 section 2.5.5 the file should be treated as stale. It is still served. policy: null bug_bounty: null evidence: - source: https://cleanshelf.com/.well-known/security.txt http_status: 200 content_type: text/plain saved: well-known/cleanshelf-security.txt kind: RFC 9116 security.txt - source: https://www.cleanshelf.com/.well-known/security.txt http_status: 200 kind: identical body on the www host maintainers: - FN: Kin Lane email: kin@apievangelist.com