generated: '2026-07-19' method: searched source: live probes of https://www.gousto.co.uk/.well-known/ host: https://www.gousto.co.uk notes: Only /.well-known/security.txt is served (RFC 9116); it declares a coordinated vulnerability-disclosure contact (vdp@gousto.co.uk) and a published disclosure policy. The remaining probes return 403 from the CDN/WAF rather than a genuine document. Gousto publishes no public API, OIDC, or OAuth authorization-server metadata. hosts: - host: https://www.gousto.co.uk documents: - path: /.well-known/security.txt status: 200 file: gousto-security.txt - path: /.well-known/openid-configuration status: 403 - path: /.well-known/oauth-authorization-server status: 403 - path: /.well-known/api-catalog status: 403 - path: /.well-known/ai-plugin.json status: 403 x-shape-fix: converted: '2026-08-20' from: documents note: Rewritten into hosts[] -> documents[], the only shape well_known_docs() in score.rb reads. A served .well-known surface recorded in any other shape scores as absent.