generated: '2026-07-19' method: searched source: live probes of getpliant.com and API hosts host: https://www.getpliant.com notes: security.txt is served at the getpliant.com apex (Canonical points there). OAuth is delegated to Auth0 tenants (eu.auth0.com), so no OIDC/OAuth discovery document is served on the getpliant.com hosts. partner.getpliant.com and customer-api.getpliant.com publish /llms.txt (200) but not /.well-known/security.txt. hosts: - host: https://www.getpliant.com documents: - path: /.well-known/security.txt status: 200 file: hihealth-security.txt - path: /.well-known/openid-configuration status: 404 - path: /.well-known/oauth-authorization-server status: 404 - path: /.well-known/api-catalog status: 404 x-shape-fix: converted: '2026-08-20' from: documents note: Rewritten into hosts[] -> documents[], the only shape well_known_docs() in score.rb reads. A served .well-known surface recorded in any other shape scores as absent.