# SendKnot - security contact, per RFC 9116. # # NOTE FOR THE PROJECT OWNER, and this is the one open question STEP LP1 # hands back: the address below is postmaster@sendknot.com, chosen because # it is a mailbox this deployment already uses (it is the ACME registration # address in infra/caddy/Caddyfile), so it is known to exist and to be read. # It was NOT invented for this file. If you would rather publish a dedicated # security@sendknot.com, create that mailbox in the Console and change the # two Contact lines here - nothing else references it. # # THE EXPIRES FIELD IS MANDATORY in RFC 9116 and a past date makes the whole # file invalid, so it must be refreshed. Set one year out from the LP1 build. # It is a static file, so nothing renews it automatically - that is a # deliberate simplicity over a generated endpoint, and this comment is the # reminder that comes with it. Contact: mailto:postmaster@sendknot.com Expires: 2027-08-27T00:00:00.000Z Preferred-Languages: en, bn Canonical: https://sendknot.com/.well-known/security.txt # What is in scope: sendknot.com, app.sendknot.com, account.sendknot.com, # mail.sendknot.com and the sending and receiving mail servers behind them. # # What is not: denial-of-service testing of any kind, and automated # scanning at a rate that degrades service for customers. Please do not # test against another customer's domain or mailbox. # # There is no bug-bounty programme and no payment. Reports are read and # answered by a person.