generated: '2026-09-05' method: probed probe: true source: https://www.clevelandcliffs.com/security.txt note: >- Cleveland-Cliffs publishes an RFC 9116 security.txt naming a security contact, on three of its own hosts. It is a thin one - Contact is the general corporate contact form rather than a security mailbox, there is no Policy: field and therefore no published disclosure policy, no bug-bounty program (no HackerOne / Bugcrowd / Intigriti listing was found), and every copy carries an Expires value that has already elapsed. Recorded as a real but stale disclosure channel; an expired security.txt is, by RFC 9116, one that should no longer be relied upon. policy: [] contact: - https://www.clevelandcliffs.com/contact expired: true expires: - {file: cleveland-cliffs-security.txt, value: '12-31-2025T00:00:00.000Z'} - {file: cleveland-cliffs-isupplier-security.txt, value: '2025-12-31T17:59:00.000Z'} - {file: cleveland-cliffs-fptscrap-security.txt, value: '2024-12-31T22:59:00.000Z'} bug_bounty: none-found evidence: - {source: 'https://www.clevelandcliffs.com/security.txt', kind: security.txt, http_status: 200, content_type: 'text/plain;charset=UTF-8', file: well-known/cleveland-cliffs-security.txt} - {source: 'https://isupplier.cliffssteel.com/.well-known/security.txt', kind: security.txt, http_status: 200, content_type: text/plain, file: well-known/cleveland-cliffs-isupplier-security.txt} - {source: 'https://portal.fptscrap.com/.well-known/security.txt', kind: security.txt, http_status: 200, content_type: text/plain, file: well-known/cleveland-cliffs-fptscrap-security.txt} - {source: 'https://www.clevelandcliffs.com/.well-known/security.txt', kind: negative, http_status: 404}