# briven security disclosure policy # RFC 9116 — https://www.rfc-editor.org/rfc/rfc9116 Contact: mailto:security@flndrn.com Expires: 2027-05-21T00:00:00.000Z Preferred-Languages: en, nl, fr Canonical: https://briven.tech/.well-known/security.txt Policy: https://docs.briven.tech/trust Acknowledgments: https://docs.briven.tech/trust#acknowledgments # We commit to: # 1. acknowledging valid reports within 72 hours. # 2. patching critical vulnerabilities within 14 days of triage. # 3. publicly crediting researchers (opt-in) on docs.briven.tech/trust. # # In scope: briven.tech (managed platform), docs.briven.tech, api.briven.tech, # realtime.briven.tech, the briven-core open-source codebase # at code.konnos.org/flndrn/briven. # # Out of scope: third-party services we use (Polar, Mittera, Hostinger, # Cloudflare) — report those to the respective vendor. # Social-engineering attacks against staff or customers. # Physical-security tests of any briven-operated facility. # # Please do NOT: # - exfiltrate or modify other customers' data # - run automated scanners that meaningfully impact availability # - publicly disclose before we've had a chance to patch (14 days # for criticals, 90 days otherwise)