generated: '2026-08-26' method: probed source: https://www.peekpro.com/.well-known/security.txt security_txt: served: true url: https://www.peekpro.com/.well-known/security.txt http_status: 200 content_type: text/plain; charset=utf-8 canonical: https://peekpro.com/.well-known/security.txt contact: mailto:security@peek.com expires: '2027-05-19T00:00:00.000Z' preferred_languages: en expired: false file: well-known/peek-security.txt fields_present: [Contact, Expires, Preferred-Languages, Canonical] fields_absent: [Policy, Encryption, Acknowledgments, Hiring, CSAF] disclosure_channel: type: email address: security@peek.com documented_policy_url: null bug_bounty: program: null platforms_checked: [HackerOne, Bugcrowd, Intigriti] found: false grade: contact-only notes: - >- Peek publishes a valid, unexpired RFC 9116 security.txt with a dedicated security@peek.com contact — a real, machine-discoverable disclosure channel. It carries no Policy: line, so there is no published disclosure policy or safe-harbour statement to read, and no bug bounty program was found. - >- The security.txt is served only from the Peek Pro marketing host (www.peekpro.com). peek.com, octo.peek.com and octodocs.peek.com all 404 on /.well-known/security.txt, so a researcher who starts at the API host or the consumer marketplace will not find it. The Canonical field points at peekpro.com/.well-known/security.txt. x-evidence: - url: https://www.peekpro.com/.well-known/security.txt http_status: 200 fetched: '2026-08-26' - url: https://www.peek.com/.well-known/security.txt http_status: 404 fetched: '2026-08-26' - url: https://octo.peek.com/.well-known/security.txt http_status: 404 fetched: '2026-08-26'