generated: '2026-08-01' method: probed probe: true source: https://earthoptics.com/.well-known/security.txt status: unverified-placeholder verified: false summary: 'EarthOptics serves an RFC 9116 security.txt at https://earthoptics.com/.well-known/security.txt (HTTP 200, text/plain), but the file is unmodified Craft CMS scaffolding: the required Contact is the literal placeholder "user@example.com", and every URL it advertises returns 404. There is no evidence of an operating vulnerability disclosure program, bug bounty, or security contact. Recorded as a negative finding — no Security / SecurityPolicy pointer is emitted, because none is earned.' policy: [] contact: [] advertised: - field: Contact value: user@example.com verdict: placeholder note: RFC 9116 required field left at the template default value - field: Policy value: https://earthoptics.com/security-policy http_status: 404 verdict: broken - field: Acknowledgements value: https://earthoptics.com/hall-of-fame http_status: 404 verdict: broken - field: Encryption value: https://earthoptics.com/pgp-key.txt http_status: 404 verdict: broken - field: Expiration value: '2027-08-01T05:02:48-07:00' verdict: dynamic note: rendered one year from request date by the CMS template, not a curated expiry bug_bounty: hackerone: false bugcrowd: false intigriti: false searched: true pages_probed: - url: https://earthoptics.com/security-policy http_status: 404 - url: https://earthoptics.com/hall-of-fame http_status: 404 - url: https://earthoptics.com/pgp-key.txt http_status: 404 - url: https://security.earthoptics.com/ http_status: 0 note: does not resolve - url: https://trust.earthoptics.com/ http_status: 0 note: does not resolve evidence: - source: https://earthoptics.com/.well-known/security.txt kind: security.txt (live probe) http_status: 200 content_type: text/plain; charset=utf-8 file: ../well-known/earth-optics-security.txt x-evidence: fetched: '2026-08-01' url: https://earthoptics.com/.well-known/security.txt http_status: 200