generated: '2026-08-05' method: searched probe: true source: https://www.willowwealth.com/.well-known/security.txt policy: - https://www.willowwealth.com/vulnerability-disclosure-policy contact: - mailto:security@willowwealth.com preferred_languages: - en canonical: https://www.willowwealth.com/.well-known/security.txt expires: '2028-06-01T03:59:00.000Z' hiring: https://www.willowwealth.com/careers bug_bounty: null bug_bounty_note: >- No HackerOne, Bugcrowd or Intigriti program was found for willowwealth.com or the legacy yieldstreet.com. The RFC 9116 security.txt names a first-party disclosure policy page and a security@ mailbox only. evidence: - source: well-known/yieldstreet-security.txt kind: security.txt url: https://www.willowwealth.com/.well-known/security.txt http_status: 200 content_type: text/plain - source: https://www.willowwealth.com/vulnerability-disclosure-policy kind: disclosure-policy-page http_status: 403 note: >- Asserted by the provider's own security.txt Policy field. The page body could not be read directly - a Cloudflare bot-management interstitial answered 403 for every HTML path on this host.