generated: '2026-08-12' method: searched source: https://api.sharpspring.com/.well-known/security.txt note: >- Probed the /.well-known/ discovery surface on every SharpSpring host found in apis.yml and in the documented API base URL. A real RFC 9116 security.txt is served on the application/API hosts (api.sharpspring.com, app.sharpspring.com and the tenant domain marketingautomation.services) — identical bytes on all three. The marketing site sharpspring.com serves nothing under /.well-known/ and answers its WordPress 404 page. All other well-known paths on the API/app hosts answer 307 to the host root (the Constant Contact login) rather than a document, so they are recorded as misses. status.sharpspring.com serves a security.txt too, but it is Atlassian's vendor-signed Statuspage file (Canonical: atlassian.com), not a SharpSpring document, and is therefore NOT credited here. hosts: - host: https://api.sharpspring.com documents: - path: /.well-known/security.txt status: 200 content_type: text/plain file: sharpspring-security.txt - path: /.well-known/openid-configuration status: 307 note: redirects to https://api.sharpspring.com/ (login shell) — not a document - path: /.well-known/oauth-authorization-server status: 307 note: redirects to https://api.sharpspring.com/ (login shell) — not a document - path: /.well-known/api-catalog status: 307 - path: /.well-known/ai-plugin.json status: 307 - path: /.well-known/agent-card.json status: 307 - path: /.well-known/agent.json status: 307 - path: /llms.txt status: 307 - host: https://app.sharpspring.com documents: - path: /.well-known/security.txt status: 200 content_type: text/plain note: byte-identical to the api.sharpspring.com copy - path: /.well-known/openid-configuration status: 307 - path: /.well-known/oauth-authorization-server status: 307 - path: /.well-known/api-catalog status: 307 - path: /.well-known/ai-plugin.json status: 307 - path: /.well-known/agent-card.json status: 307 - path: /.well-known/agent.json status: 307 - host: https://marketingautomation.services documents: - path: /.well-known/security.txt status: 200 content_type: text/plain note: byte-identical to the api.sharpspring.com copy; this is the tenant/app cookie domain - host: https://sharpspring.com documents: - path: /.well-known/security.txt status: 404 note: WordPress 404 HTML body - path: /.well-known/openid-configuration status: 404 - path: /.well-known/oauth-authorization-server status: 404 - path: /.well-known/api-catalog status: 404 - path: /.well-known/ai-plugin.json status: 404 - path: /.well-known/agent-card.json status: 404 - path: /.well-known/agent.json status: 404 - path: /llms.txt status: 404 - path: /.well-known/sharpspring.gpg.txt status: 404 note: >- The Encryption: field of the served security.txt points here, but the PGP key it names is gone — a dangling reference in the provider's own RFC 9116 document. security_txt: file: sharpspring-security.txt fields: contact: security [ at ] sharpspring.com encryption: https://sharpspring.com/.well-known/sharpspring.gpg.txt permission: none policy: http://sharpspring.com/legal/privacy/ hiring: https://careers.sharpspring.com/ rfc9116_gaps: - no Expires field (RFC 9116 §2.5.5 requires it) - Contact is obfuscated ("security [ at ] sharpspring.com") rather than a mailto: URI - Policy points at the privacy notice over plain http://, not a vulnerability disclosure policy - Encryption URL returns 404 - not PGP-signed x-evidence: fetched: '2026-08-12' probes: - url: https://api.sharpspring.com/.well-known/security.txt status: 200 - url: https://app.sharpspring.com/.well-known/security.txt status: 200 - url: https://marketingautomation.services/.well-known/security.txt status: 200 - url: https://sharpspring.com/.well-known/security.txt status: 404 - url: https://sharpspring.com/.well-known/sharpspring.gpg.txt status: 404