generated: '2026-07-31' method: searched probe: true source: https://sunbit.com/.well-known/security.txt contact: - mailto:security@sunbit.com policy: [] encryption: - https://sunbit.com/pgp-key.txt preferred_languages: - en expires: '2022-12-31T21:59:00.000Z' expired: true security_txt: present: true url: https://sunbit.com/.well-known/security.txt http_status: 200 content_type: text/plain file: well-known/sunbit-security.txt rfc9116_fields_present: - Contact - Expires - Encryption - Preferred-Languages rfc9116_fields_missing: - Policy - Acknowledgments - Canonical - Hiring signed: false note: >- Well-formed and reachable, but the Expires value is 2022-12-31 — more than three years stale as of this probe. RFC 9116 requires the file be refreshed before it expires, so a researcher following the spec should treat this contact as unmaintained. bug_bounty: program: none found platforms_checked: - HackerOne - Bugcrowd - Intigriti result: no public program found disclosure_pages_probed: - url: https://sunbit.com/security/ status: 404 - url: https://sunbit.com/responsible-disclosure/ status: 404 - url: https://sunbit.com/vulnerability-disclosure/ status: 404 - url: https://sunbit.com/compliance/ status: 404 - url: https://security.sunbit.com/ status: NXDOMAIN - url: https://trust.sunbit.com/ status: NXDOMAIN evidence: - source: https://sunbit.com/.well-known/security.txt kind: security.txt (live probe) fetched: '2026-07-31' http_status: 200 - source: https://sunbit.com/pgp-key.txt kind: encryption key referenced by security.txt fetched: '2026-07-31' http_status: 200 gaps: - security.txt is expired (Expires 2022-12-31) and carries no Policy field, so there is a contact address but no published disclosure process or safe-harbour statement. - No public bug bounty program on any major platform. - No dedicated security, trust, or responsible-disclosure page anywhere on sunbit.com.