# Security policy for DefenceOS (RFC 9116, https://www.rfc-editor.org/rfc/rfc9116). # # If you've found a security issue in this product, please report it to the # contact address below. Please do NOT file a public issue — we prefer # coordinated disclosure so affected deployments can be notified before # the issue becomes exploitable in the wild. # # Expected initial response: within 5 working days. # Preferred locale for reports: English. # # Follow-ups to complete this record (tracked as ACC-04, issue #109): # - Publish the full CVD policy at a public URL and add a `Policy:` line. # - Add a `Canonical:` line pointing at the production URL of this file # (e.g. `https://app.skansar.com/.well-known/security.txt`). # - Add an `Encryption:` line linking a PGP public key if the mailbox # supports encrypted submissions. # `Contact:` and `Expires:` are the only mandatory RFC 9116 fields; the # others are optional. This file is valid as-is; the follow-ups above # are quality improvements, not blockers. Contact: mailto:security@skansar.com Expires: 2027-04-20T00:00:00.000Z Preferred-Languages: en