security.txt 1.3 KB

1234567891011121314151617181920212223242526272829
  1. # briven security disclosure policy
  2. # RFC 9116 — https://www.rfc-editor.org/rfc/rfc9116
  3. Contact: mailto:security@flndrn.com
  4. Expires: 2027-05-21T00:00:00.000Z
  5. Preferred-Languages: en, nl, fr
  6. Canonical: https://briven.tech/.well-known/security.txt
  7. Policy: https://docs.briven.tech/trust
  8. Acknowledgments: https://docs.briven.tech/trust#acknowledgments
  9. # We commit to:
  10. # 1. acknowledging valid reports within 72 hours.
  11. # 2. patching critical vulnerabilities within 14 days of triage.
  12. # 3. publicly crediting researchers (opt-in) on docs.briven.tech/trust.
  13. #
  14. # In scope: briven.tech (managed platform), docs.briven.tech, api.briven.tech,
  15. # realtime.briven.tech, the briven-core open-source codebase
  16. # at code.konnos.org/flndrn/briven.
  17. #
  18. # Out of scope: third-party services we use (Polar, Mittera, Hostinger,
  19. # Cloudflare) — report those to the respective vendor.
  20. # Social-engineering attacks against staff or customers.
  21. # Physical-security tests of any briven-operated facility.
  22. #
  23. # Please do NOT:
  24. # - exfiltrate or modify other customers' data
  25. # - run automated scanners that meaningfully impact availability
  26. # - publicly disclose before we've had a chance to patch (14 days
  27. # for criticals, 90 days otherwise)