generated: '2026-08-28' method: probed source: https://x.com/.well-known/security.txt description: >- X operates a public vulnerability disclosure programme through HackerOne, advertised in a PGP-signed RFC 9116 security.txt served from the x.com root. program: type: bug-bounty platform: HackerOne url: https://hackerone.com/twitter public: true security_txt: url: https://x.com/.well-known/security.txt http_status: 200 content_type: text/plain file: ../well-known/x-security.txt signed: true signature: OpenPGP clearsigned (SHA512) fields: Contact: https://hackerone.com/twitter Encryption: https://twitter.com/security/pgp-key.txt Canonical: https://twitter.com/.well-known/security.txt Expires: '2024-01-01T06:00:00.000Z' Hiring: https://careers.twitter.com policy_url: null findings: - severity: note finding: >- The served security.txt is past its own stated Expires date (2024-01-01). RFC 9116 says a researcher should not trust an expired document, so the file X serves today formally disclaims itself even though the HackerOne programme behind it is live. - severity: note finding: >- Canonical, Encryption and Hiring all still point at twitter.com / careers.twitter.com rather than x.com — the document predates the rebrand. - severity: note finding: >- No security.txt is served on the API or documentation hosts. api.x.com, developer.x.com and docs.x.com all 404 on /.well-known/security.txt, so a researcher starting from the API surface finds nothing. - severity: note finding: 'No Policy: field is present, so there is no linked disclosure policy document.' probes: - url: https://x.com/.well-known/security.txt status: 200 - url: https://api.x.com/.well-known/security.txt status: 404 - url: https://developer.x.com/.well-known/security.txt status: 404 - url: https://docs.x.com/.well-known/security.txt status: 404