# Calwyn — security contact (RFC 9116) # # If you have found a vulnerability in Calwyn, please write to the address below before disclosing it # publicly. Calwyn is run by one person, so expect a human reply rather than an automated triage # ticket, and expect it within a few days rather than a few minutes. # # There is no bug-bounty programme and no payment. What you will get is a straight answer about # whether the issue is real, what is being done about it, and credit if you want it. Contact: mailto:security@calwyn.app Expires: 2027-07-31T00:00:00.000Z Preferred-Languages: en Canonical: https://calwyn.app/.well-known/security.txt Policy: https://calwyn.app/terms # Out of scope, so nobody spends their time on them: # - Reports produced only by an automated scanner, with no demonstrated impact # - Missing hardening headers with no exploitable consequence # - Rate limiting, volumetric denial of service # - Social engineering of the founder or of any vendor's support desk # # In scope and genuinely wanted: anything that reaches another user's résumé, applications, contacts # or account. Tenancy is the boundary that matters most here.