generated: '2026-09-18' method: searched probe: true source: https://www.sound.ag/.well-known/security.txt policy: - https://www.sound.ag/security-policy contact: - whit+dev@onedesigncompany.com evidence: - source: https://www.sound.ag/.well-known/security.txt kind: security.txt (live probe) note: "Served, but thin: the security.txt carries the two RFC 9116 required fields (Contact, Expiration 2027-09-18)\ \ and nothing else that resolves. Contact is whit+dev@onedesigncompany.com \u2014 One Design Company is the agency\ \ that built the Craft CMS site (per https://www.sound.ag/humans.txt), not a Sound Agriculture security team.\ \ The optional Policy (https://www.sound.ag/security-policy), Encryption (https://www.sound.ag/pgp-key.txt) and\ \ Acknowledgements (https://www.sound.ag/hall-of-fame) URLs all returned 404 on 2026-09-18. No bug bounty program\ \ was found on HackerOne, Bugcrowd or Intigriti. Treat this as a reachable disclosure contact, not a published\ \ disclosure policy." policy_status: https://www.sound.ag/security-policy: 404 https://www.sound.ag/pgp-key.txt: 404 https://www.sound.ag/hall-of-fame: 404 contact_note: third-party web agency address, not a company security alias