generated: '2026-08-02' method: probed probe: true source: https://app.shipmonk.com/.well-known/security.txt description: >- ShipMonk publishes an RFC 9116 security.txt naming a security contact address. No bug-bounty program (HackerOne / Bugcrowd / Intigriti), no dedicated responsible-disclosure page, and no Policy: field were found; the disclosure route is the published contact. policy: [] contact: - mailto:security@shipmonk.com - https://twitter.com/ShipMonkDevs canonical: https://app.shipmonk.com/.well-known/security.txt preferred_languages: [en, cs] security_txt: present: true file: well-known/shipmonk-security.txt fields_present: [Contact, Canonical, Preferred-Languages] fields_missing: [Expires, Policy, Encryption, Acknowledgments, Hiring] rfc9116_compliant: false note: >- RFC 9116 requires an Expires field; it is absent, so the document is non-conformant even though it is served and resolvable. bug_bounty: present: false platforms_checked: [hackerone, bugcrowd, intigriti] evidence: - {source: 'https://app.shipmonk.com/.well-known/security.txt', kind: security.txt, http_status: 200, content_type: text/plain} - {source: 'https://sandbox.shipmonk.dev/.well-known/security.txt', kind: security.txt, http_status: 200, content_type: text/plain} - {source: 'https://www.shipmonk.com/.well-known/security.txt', kind: security.txt, http_status: 404} - {source: 'https://api.shipmonk.com/.well-known/security.txt', kind: security.txt, http_status: 404}