# SieveGuard responsible-disclosure policy # RFC 9116 — https://www.rfc-editor.org/rfc/rfc9116 # # If you discover a security vulnerability in the SieveGuard service, please report it # privately to the contact below. We will acknowledge within 2 business days, work with # you on a coordinated disclosure timeline, and credit you on the acknowledgements page # (unless you ask to stay anonymous). No bug-bounty payouts are offered at this stage, # but we appreciate every report. # # Annual rotation: update the Expires field before the date below. RFC 9116 requires it # to be in the future at all times. Convention is to set it ~1 year out. Contact: mailto:security@sieveguard.com Expires: 2027-06-12T00:00:00.000Z Preferred-Languages: en Canonical: https://sieveguard.com/.well-known/security.txt