generated: '2026-09-04' method: searched probe: true source: >- https://wellfound.com/.well-known/security.txt (200), plus negative probes of HackerOne, Bugcrowd and the Wellfound site on 2026-09-04 program: published: true form: security.txt contact only bug_bounty: false disclosure_policy_page: null contact: - mailto:security@wellfound.com security_txt: url: https://wellfound.com/.well-known/security.txt http_status: 200 content_type: text/plain bytes: 62 file: well-known/wellfound-security.txt fields_present: - Contact fields_absent: - Expires - Policy - Encryption - Preferred-Languages - Canonical - Acknowledgments - Hiring rfc9116_conformant: false rfc9116_note: >- Expires is a MUST in RFC 9116 and is absent, so the document is served but not conformant. The file is two useful lines - a comment and a Contact - and nothing more. also_served_on: - https://reach.wellfound.com/.well-known/security.txt - https://cloud.wellfound.com/.well-known/security.txt note: the same 62-byte document is served on three Wellfound hosts, which is consistent first-party publication rather than a one-off. negative_probes: - url: https://hackerone.com/wellfound status: 404 - url: https://bugcrowd.com/wellfound status: 404 - url: https://wellfound.com/security status: 404 - url: https://wellfound.com/vulnerability-disclosure status: 403 note: rewrites to /company/vulnerability-disclosure and hits the Cloudflare managed challenge that guards company-profile routes - not a disclosure page. - url: https://status.wellfound.com/.well-known/security.txt status: 200 note: >- NOT WELLFOUND'S - Atlassian's PGP-signed vendor security.txt served by Statuspage (Contact security@atlassian.com). Explicitly not credited to Wellfound. evidence: - source: https://wellfound.com/.well-known/security.txt kind: RFC 9116 security.txt, fetched live 2026-09-04, HTTP 200 - source: well-known/wellfound-security.txt kind: saved verbatim copy summary: >- Wellfound publishes a reachable security contact and nothing else. There is no disclosure policy, no safe-harbour statement, no bounty program on either major platform, and no Expires field, so a researcher has an address but no published terms.