generated: '2026-08-30' method: probed probe: true source: https://www.toogoodtogo.com/.well-known/security.txt description: >- Too Good To Go serves an RFC 9116 security.txt naming a single security contact. The file is served identically from the marketing host and from both live API backends. It carries only a Contact field — no Policy, Expires, Encryption, Acknowledgments, Preferred-Languages or Canonical field — so it is a valid but minimal disclosure signal. No public bug bounty program (HackerOne, Bugcrowd, Intigriti) and no standalone responsible-disclosure page were found. contact: - mailto:security@toogoodtogo.com policy_url: null bug_bounty: present: false platform: null note: No HackerOne / Bugcrowd / Intigriti program found for toogoodtogo.com. security_txt: file: well-known/too-good-to-go-security.txt rfc: RFC 9116 fields_present: - Contact fields_missing: - Expires - Policy - Encryption - Acknowledgments - Preferred-Languages - Canonical note: >- RFC 9116 requires an Expires field; this file omits it, so it is non-conformant to the letter of the RFC while still being a real, served, machine-readable contact document. evidence: - url: https://www.toogoodtogo.com/.well-known/security.txt http_status: 200 content_type: text/plain; charset=utf-8 - url: https://api.toogoodtogo.com/.well-known/security.txt http_status: 200 - url: https://apptoogoodtogo.com/.well-known/security.txt http_status: 200