generated: '2026-08-26' method: probed source: https://moz.com/.well-known/security.txt document: well-known/moz-security.txt summary: >- Moz serves a real RFC 9116 security.txt at https://moz.com/.well-known/security.txt (HTTP 200) with a working contact address, so a reporter has somewhere to send a finding. Every other field in that document, however, points at a page that no longer exists, and the document itself was expired at the time of probing. program_type: security.txt contact only bug_bounty: published: false platforms_checked: [HackerOne, Bugcrowd, Intigriti] found: none contact: - kind: email value: inboundeng+cms@moz.com source: 'Contact: field of https://moz.com/.well-known/security.txt' status: live (address, not probed for delivery) policy: - url: https://moz.com/security-policy advertised_in: 'Policy: field of security.txt' http_status: 404 checked: '2026-08-26' note: The advertised security policy page is not served. encryption: - url: https://moz.com/pgp-key.txt advertised_in: 'Encryption: field of security.txt' http_status: 404 checked: '2026-08-26' acknowledgements: - url: https://moz.com/hall-of-fame advertised_in: 'Acknowledgements: field of security.txt' http_status: 404 checked: '2026-08-26' expiration: value: '2026-08-25T19:48:09-07:00' expired: true checked: '2026-08-26' note: >- RFC 9116 requires the Expires field and says a document past its expiry should be considered stale. This one lapsed one day before probing. evidence: - url: https://moz.com/.well-known/security.txt status: 200 - url: https://moz.com/security-policy status: 404 - url: https://moz.com/pgp-key.txt status: 404 - url: https://moz.com/hall-of-fame status: 404 finding: >- Three of the five advertised URLs in Moz's security.txt are dead and the document has expired. This is a small, cheap, provider-side fix - restore or remove the Policy, Encryption and Acknowledgements lines and roll the Expires date forward - and it is worth flagging back to Moz rather than scoring silently.