# SBVault vulnerability disclosure # # RFC 9116. Served from client/.well-known/security.txt by the existing # express.static mount on client/ (verified: Express serves this path without # any dotfiles option, so no config change was needed). # # Expires is REQUIRED by the RFC and must be a future date, so this file has a # maintenance cost by design: a stale security.txt is treated as untrustworthy # by researchers and scanners. Update the date when you review the contacts. Contact: mailto:security@sbvault.app Expires: 2027-08-01T00:00:00.000Z Preferred-Languages: en Canonical: https://sbvault.app/.well-known/security.txt Policy: https://sbvault.app/security.html # security@sbvault.app is an ImprovMX alias forwarding to the shared SBVault # inbox. It is monitored, but it is not a 24/7 pager: expect acknowledgement in # business days, not hours. Please do not include exploit details that would # harm users if the message were intercepted in transit.