generated: '2026-08-01' method: searched probe: true source: https://happyrobot.ai/.well-known/security.txt security_txt: url: https://happyrobot.ai/.well-known/security.txt http_status: 200 spec: RFC 9116 served_on_hosts: - happyrobot.ai - platform.happyrobot.ai - app.happyrobot.ai fields: Contact: mailto:security@happyrobot.ai Expires: '2026-09-10T13:32:00Z' Hiring: https://jobs.ashbyhq.com/happyrobot.ai Preferred-Languages: en, es contact: - mailto:security@happyrobot.ai policy: [] bug_bounty: program: null platform: null note: >- No HackerOne, Bugcrowd or Intigriti program was found, and no /security, /responsible-disclosure or /vulnerability-disclosure page exists on the marketing site (all 404). gaps: - No `Policy:` field in security.txt, so there is no published disclosure policy to point a researcher at — only an email address. - No `Encryption:` field (no PGP key for reporting). - No `Canonical:` field. - The `Expires` value is 2026-09-10, roughly six weeks after this probe — the file will need rotation soon or it becomes non-conformant. - security.txt is not served on www.happyrobot.ai (404), only on the apex and the app/platform hosts. evidence: - source: https://happyrobot.ai/.well-known/security.txt kind: security.txt http_status: 200 - source: well-known/happyrobot-security.txt kind: harvested copy x-evidence: fetched: '2026-08-01' negative_probes: - url: https://www.happyrobot.ai/security http_status: 404 - url: https://www.happyrobot.ai/trust http_status: 404 - url: https://security.happyrobot.ai result: does not resolve - url: https://www.happyrobot.ai/.well-known/security.txt http_status: 404