# Superparent security contact — RFC 9116 (https://www.rfc-editor.org/rfc/rfc9116) # Served from the web app's public/ dir at: # https://app.superparent.io/.well-known/security.txt # Report a vulnerability: security@superparent.io # # NOTE FOR OPERATORS: # - `Expires` MUST stay in the future. Refresh this file ~annually (ties to # the CASA annual reverification). See docs/security/casa/policies/. # - `security@superparent.io` MUST be a monitored inbox (HUMAN action). # - `Policy` points at the Vulnerability Disclosure Policy page. Publish that # page (content: docs/security/casa/policies/vulnerability-disclosure.md) # before/at submission so this link is not a 404. # - `Encryption` / `Acknowledgments` lines are intentionally omitted: no PGP # key or hall-of-fame page exists yet. Do NOT add lines that 404. Contact: mailto:security@superparent.io Expires: 2027-07-07T00:00:00.000Z Policy: https://superparent.io/security/vulnerability-disclosure Preferred-Languages: en Canonical: https://app.superparent.io/.well-known/security.txt