# Vaethra security contact — RFC 9116 # # A plain-text file, not a redirect to an HTML page: a scanner reads the target # of a redirect as the policy, and a document with a in it is not one. Contact: mailto:security@vaethra.com Contact: https://vaethra.com/security/vulnerability-management Expires: 2027-09-07T00:00:00.000Z Preferred-Languages: en, de Canonical: https://vaethra.com/.well-known/security.txt Policy: https://vaethra.com/security/vulnerability-management Hiring: https://vaethra.com/about # What to expect, in full, at the Policy URL above: # Acknowledgement within 2 business days. # Initial assessment and severity within 5 business days. # Progress updates every 7 days until closed. # Fixes: 24h critical, 7d high, 30d medium, 90d low. # Credit in the public changelog if you want it. # # There is no bug bounty. We would rather say so than imply one. # # Please do not run automated scans against api.vaethra.com — scanner load is # indistinguishable from abuse and will be rate-limited and logged as such. # Write first and we will arrange a window.