# Stoneledger — how to report a security problem # RFC 9116. Plain text on purpose: this file is read by scanners and by people. # The full policy, including what is in scope and what we undertake, is at # https://stoneledgeruk.co.uk/legal.html#security Contact: mailto:security@stoneledgeruk.co.uk Expires: 2027-09-20T00:00:00.000Z Preferred-Languages: en Canonical: https://stoneledgeruk.co.uk/.well-known/security.txt Policy: https://stoneledgeruk.co.uk/legal.html#security # We acknowledge within 2 working days. We ask for 90 days before disclosure. # We do not pay bounties. We will credit you if you want to be credited. # Report in good faith and within the policy and we will not take legal # action against you. # # Out of scope: our suppliers' own infrastructure — DigitalOcean, Cloudflare, # Resend and Stripe. Report those to them. # # TODO before this goes live: set Expires to twelve months from the launch # date, and renew it every year. A stale Expires makes the file invalid.