# GLACIS Technologies, Inc. -- security contact information. # Format: RFC 9116 (https://www.rfc-editor.org/rfc/rfc9116). # # Full policy: scope, safe harbor, response targets, and what we ask of # you while you are testing: # https://www.glacis.io/security-disclosure # # There is no bug bounty. We do not pay for reports today, and we do not # require an NDA to receive one. Reports are read by a person. Contact: mailto:security@glacis.io Contact: https://www.glacis.io/security-disclosure Expires: 2027-02-13T23:59:59.000Z Preferred-Languages: en Canonical: https://www.glacis.io/.well-known/security.txt Canonical: https://glacis.io/.well-known/security.txt Policy: https://www.glacis.io/security-disclosure # Systems we operate and can authorize testing against are listed in the # policy above. A Glacis deployment running inside a customer environment # is not ours to authorize -- tell us and we will contact the operator. # # Findings in the OVERT receipt standard itself (schema, canonicalization, # signing, hash chain, verification procedure) are in scope even when no # Glacis system is affected. The standard is published at https://overt.is # and any receipt can be checked at https://verify.glacis.io without an # account. # # If the Expires date above has passed, treat this file as stale and mail # security@glacis.io anyway.