generated: '2026-09-19' method: searched probe: true source: well-known/xguardgate-com-security.txt policy: - https://github.com/moelayyan90/XGuard/security contact: - mailto:mo.elayyan2023@gmail.com evidence: - source: well-known/xguardgate-com-security.txt kind: security.txt (previously harvested) docs: - https://xguardgate.com/security - https://xguardgate.com/.well-known/security.txt pages: - url: https://xguardgate.com/security status: 200 fetched: '2026-09-19' title: XGuard Security note: States the Secretless Egress security boundary (credentials encrypted at rest, injected only after host/path/method/lifetime/budget checks, redirects not followed, private and XGuard-owned targets blocked) and names the report-to address, linking security.txt. - url: https://github.com/moelayyan90/XGuard/security status: 200 fetched: '2026-09-19' note: 'The security.txt Policy URL is the repository Security tab; the repository has no SECURITY.md (raw SECURITY.md and .github/SECURITY.md both 404, community profile security: null), so no disclosure timeline, scope or safe-harbour statement is published.' bug_bounty: program: null note: No HackerOne, Bugcrowd, Intigriti or self-hosted bounty found; disclosure is by email only. security_txt: file: well-known/xguardgate-com-security.txt expires: '2027-08-27T00:00:00Z' canonical: - https://xguardgate.com/.well-known/security.txt - https://api.xguardgate.com/.well-known/security.txt preferred_languages: en, ar signed: false note: A real, current RFC 9116 security.txt with a monitored contact and a Policy link, served from both the website and the API host; the policy target is an empty GitHub Security tab, so the program is a contact channel rather than a documented disclosure policy. The Security pointer in apis.yml is emitted on the strength of the served security.txt.