generated: '2026-08-26' method: searched probe: true source: https://www.realself.com/.well-known/security.txt summary: >- RealSelf serves an RFC 9116 security.txt at both the apex and www hosts. It names a security contact address and two Policy URLs — a security page on the marketing host and a Bugcrowd program. The Bugcrowd URL the file advertises did not resolve to a public program when probed on 2026-08-26, so the bounty program is either private (invitation-only, which Bugcrowd does not list publicly) or the pointer is stale. The disclosure contact itself is real and served. contact: - security@realself.com policy: - url: https://www.realself.com/security/ status: 403 note: >- Fastly edge answers our crawler with a reCAPTCHA "Access has been denied" interstitial for every path on the app host. Not treated as dead — RealSelf's own security.txt asserts this page, and /news on the same host returns 200. - url: https://bugcrowd.com/realself status: 404 note: >- Advertised in security.txt as a Policy URL. Bugcrowd returns "Resource not found 404" for both /realself and /engagements/realself, so no public program page exists. preferred_languages: - en bug_bounty: platform: bugcrowd advertised: true public_program_found: false evidence: https://bugcrowd.com/realself returned 404 on 2026-08-26 evidence: - url: https://www.realself.com/.well-known/security.txt status: 200 content_type: text/plain; charset=UTF-8 file: well-known/realself-security.txt - url: https://realself.com/.well-known/security.txt status: 200 - url: https://bugcrowd.com/realself status: 404 - url: https://bugcrowd.com/engagements/realself status: 404