# Vulnerability disclosure contact for CMS InfoSec Ltd (RFC 9116). # # `Expires` is mandatory under RFC 9116 and MUST be refreshed before it passes. # A stale security.txt is worse than none: it tells a researcher we are not # maintaining the file, which is a reasonable thing to conclude from it. # # `Policy` points at /security/, which is a real page in this repository at # src/pages/security.astro. Both halves have to move together: this field # pointing at a 404 is worse than no field, because a tool that follows it # reports the company as advertising a policy it does not have. The page did # not exist until this line was added, and the app was linking to it anyway. # # That page is also where safe harbour terms, a scope and a response time will # go when they are agreed. None of them is published today, and the page says # so rather than leaving a researcher to assume. Contact: mailto:security@cmsinfosec.com Expires: 2027-09-06T00:00:00.000Z Preferred-Languages: en Canonical: https://cmsinfosec.com/.well-known/security.txt Policy: https://cmsinfosec.com/security/