# security.txt for supportshot.com — RFC 9116 # # Served as a static file from apps/web/public/.well-known/, so it exists at # https://supportshot.com/.well-known/security.txt without a route. # # Expires is mandatory under RFC 9116 and must be under a year out. When it is refreshed, # refresh /security in the same change: test/marketing-claims.test.ts asserts that the # Contact address here is the one lib/legal.ts publishes and that the Policy URL below is # a page that exists. Contact: mailto:support@supportshot.com Expires: 2027-07-01T00:00:00.000Z Preferred-Languages: en Canonical: https://supportshot.com/.well-known/security.txt Policy: https://supportshot.com/security # No bug bounty. We pay nothing for reports and would rather say so before you spend a # weekend than after. What we do promise — acknowledgement in 3 business days, an # assessment in 10, no legal action over a good-faith report, and credit on request — is # on the policy page above, along with what is in and out of scope.