generated: '2026-08-28' method: searched probe: true source: well-known/macadress-security.txt contact: - mailto:hello@macadress.com evidence: - source: well-known/macadress-security.txt kind: security.txt (previously harvested) security_txt: url: https://macadress.com/.well-known/security.txt status: 200 fields: Contact: mailto:hello@macadress.com Expires: '2027-08-22T00:00:00.000Z' Canonical: https://macadress.com/.well-known/security.txt Preferred-Languages: en rfc9116: true missing_optional_fields: [Policy, Encryption, Acknowledgments, Hiring, CSAF] bug_bounty: present: false platforms_checked: [HackerOne, Bugcrowd, Intigriti] result: none found disclosure_policy_page: present: false probed: - url: https://macadress.com/security status: 404 - url: https://macadress.com/trust status: 404 note: > A valid, unexpired, canonical RFC 9116 security.txt with a working contact address — more than most providers this size publish — but it carries no Policy field, so a researcher gets an inbox and no stated terms, timeline or safe-harbour. Adding a Policy URL is the single cheapest upgrade available on this surface.