generated: '2026-09-19' method: searched probe: true source: well-known/decision-anchor-com-security.txt contact: - mailto:contact@decision-anchor.com evidence: - source: well-known/decision-anchor-com-security.txt kind: security.txt (previously harvested) - source: https://api.decision-anchor.com/.well-known/security.txt kind: security.txt (live probe) http_status: 200 fetched: '2026-09-19' - source: https://mcp.decision-anchor.com/.well-known/security.txt kind: security.txt (live probe) http_status: 200 fetched: '2026-09-19' - source: https://a2a.decision-anchor.com/.well-known/security.txt kind: security.txt (live probe) http_status: 200 fetched: '2026-09-19' summary: >- Decision Anchor publishes an RFC 9116 security.txt on each of its three service hosts (api., mcp., a2a.) with a security contact, an expiry a year out, preferred languages and a canonical URL — a disclosure channel, but not a disclosure policy: there is no Policy line, no dedicated security or responsible-disclosure page, no safe-harbour statement and no bug-bounty programme on HackerOne, Bugcrowd or Intigriti. The apex website and the two marketing microsites serve no security.txt at all. channel: contact: mailto:contact@decision-anchor.com expires: '2027-09-19' preferred_languages: [en, ko] canonical: https://api.decision-anchor.com/.well-known/security.txt policy_url: null encryption: null acknowledgments: null security_txt: - host: api.decision-anchor.com url: https://api.decision-anchor.com/.well-known/security.txt http_status: 200 content_type: text/plain; charset=utf-8 file: ../well-known/decision-anchor-com-security.txt - host: mcp.decision-anchor.com url: https://mcp.decision-anchor.com/.well-known/security.txt http_status: 200 file: ../well-known/decision-anchor-com-mcp-security.txt - host: a2a.decision-anchor.com url: https://a2a.decision-anchor.com/.well-known/security.txt http_status: 200 file: ../well-known/decision-anchor-com-a2a-security.txt - {host: decision-anchor.com, url: 'https://decision-anchor.com/.well-known/security.txt', http_status: 404} - {host: solo.decision-anchor.com, http_status: 404} - {host: business.decision-anchor.com, http_status: 404} bug_bounty: program: none found probed_note: No HackerOne, Bugcrowd or Intigriti programme under decision-anchor / decisionanchor; no /security page or security.txt Policy pointer to one. disclosure_page: url: null probed: [{url: 'https://decision-anchor.com/security', status: 404}, {url: 'https://api.decision-anchor.com/security', status: 404}] notes: - 'The Expires timestamps differ by seconds between hosts (23:04:27 vs 23:07:39 on 2027-09-19), which suggests the file is generated per request with Expires = now + 1 year rather than being a static file — a reader should not treat the expiry as a maintained commitment date.' - 'Changelog 2026-08-20 ("Dying on receipt of the tool list") records that this security.txt was unreadable to legacy-encoding clients until that date.'