generated: '2026-09-19' method: searched source: https://gate.horizonshield.dev/.well-known/security.txt docs: - https://ledger.horizonshield.dev/.well-known/security.txt - https://shield.the-horizons-innovation.com/verify-directory/ - https://ledger.horizonshield.dev/llms.txt program: RFC 9116 security.txt on two service hosts (no bug bounty platform) security_txt: - host: gate.horizonshield.dev url: https://gate.horizonshield.dev/.well-known/security.txt status: 200 file: well-known/horizonshield-dev-security.txt contact: mailto:contact@the-horizons-innovation.com policy: https://shield.the-horizons-innovation.com/verify-directory/ canonical: https://gate.horizonshield.dev/.well-known/security.txt preferred_languages: [en, ja] expires: null scope_statement: 'This service publishes verdicts about other people''s servers. If a verdict here is wrong, that is a security problem, not a support ticket. Send the endpoint, what you measured, and from where. A report that contradicts our own measurement is the most useful kind, and it will be published either way.' - host: ledger.horizonshield.dev url: https://ledger.horizonshield.dev/.well-known/security.txt status: 200 file: well-known/horizonshield-dev-ledger-security.txt contact: mailto:thehorizon.nnovation@icloud.com policy: https://ledger.horizonshield.dev/llms.txt canonical: https://ledger.horizonshield.dev/.well-known/security.txt preferred_languages: [ja, en] expires: '2027-07-26T00:00:00.000Z' scope_statement: 'This ledger is read-only and unauthenticated by design. If you find a way to make a record''s bytes disagree with its published hash, or to make a verification recipe return a result that cannot be reproduced, that is the vulnerability we most want to hear about.' absent_on: - {host: mcp.horizonshield.dev, status: 404} - {host: shield.the-horizons-innovation.com, status: 404} - {host: horizonshield.dev, status: 0, note: does not resolve} bug_bounty: null disclosure_page: null notes: >- Two RFC 9116 files with Contact and Policy lines and a stated scope of what counts as a vulnerability; the gate copy lacks the mandatory Expires field and its Policy target is the register page rather than a disclosure policy. No HackerOne / Bugcrowd / Intigriti programme and no dedicated disclosure page were found. The repository carries an ops/security_audit_20260913.md and a .gitleaks.toml, which suggest an internal practice but are not a public programme. The probe-security-programs.py script could not find these because it probes the registrable domain, which does not resolve.