generated: '2026-08-13' method: probed source: >- https://app.later.com/.well-known/security.txt (HTTP 200, probed 2026-08-13) and https://trust.later.com/ published: partial policy_url: null bug_bounty: none found safe_harbor: not stated contact: email: security@later.com source: https://app.later.com/.well-known/security.txt security_txt: url: https://app.later.com/.well-known/security.txt http_status: 200 content_type: text/plain file: well-known/later-security.txt fields_present: - Contact - Expires fields_absent: - Policy - Encryption - Acknowledgments - Preferred-Languages - Canonical - Hiring expires: '2024-06-12T07:00:00.000Z' expired: true rfc9116_note: >- RFC 9116 section 2.5.5 states a security.txt file whose Expires date has passed MUST NOT be used. This one expired on 2024-06-12, more than two years before this probe, and carries no Policy field. A reporter therefore has an email address that Later has not reaffirmed since 2024, and no published policy, scope or safe-harbour statement. probes: - url: https://app.later.com/.well-known/security.txt http_status: 200 - url: https://later.com/.well-known/security.txt http_status: 404 - url: https://api.mavrck.co/.well-known/security.txt http_status: 404 - url: https://later.com/security/ http_status: 404 - url: https://trust.later.com/ http_status: 200 finding: no vulnerability disclosure policy or bug bounty linked bounty_platforms_checked: - HackerOne - Bugcrowd - Intigriti bounty_platforms_found: []