generated: '2026-08-22' method: searched probe: true source: https://app.neuroblu.ai/.well-known/security.txt contact: - mailto:disclosure@holmusk.com policy: [] note: >- Holmusk serves an RFC 9116 security.txt from the NeuroBlu application host only (https://app.neuroblu.ai/.well-known/security.txt — HTTP 200, text/plain, 73 bytes). It carries a Contact and an Expires field and nothing else: no Policy, no Encryption, no Preferred-Languages, no Canonical. The Expires value is 2025-12-31T00:00:00.000Z, which was in the past when probed on 2026-08-22, so the document is STALE under RFC 9116 §2.5.4 even though it is served. The corporate site (www.holmusk.com) and the product site (www.neuroblu.ai) serve no security.txt (404 on both). No bug bounty program was found on HackerOne, Bugcrowd or Intigriti. security_txt: url: https://app.neuroblu.ai/.well-known/security.txt status: 200 file: well-known/holmusk-security.txt fields: [Contact, Expires] expires: '2025-12-31T00:00:00.000Z' expired: true last_modified: '2026-08-12T09:20:16Z' bug_bounty: none-found internal_program: documented: true source: https://policy.holmusk.com/ detail: >- Holmusk publishes a vulnerability management policy: "External penetration testing is performed annually by a third party. Internal penetration testing is performed quarterly," with quarterly vulnerability report review through its Quality Management System. This is an internal testing program, not an external researcher disclosure program. evidence: - source: https://app.neuroblu.ai/.well-known/security.txt status: 200 kind: security.txt - source: https://www.holmusk.com/.well-known/security.txt status: 404 kind: security.txt - source: https://www.neuroblu.ai/.well-known/security.txt status: 404 kind: security.txt - source: https://policy.holmusk.com/ status: 200 kind: vulnerability-management-policy