# security.txt for rivet.technology — RFC 9116 # Served from rivet-client public/.well-known/security.txt. # # Policy points at /security#disclosure, which carries the disclosure terms # (How to report, What to expect, Scope, Rules of engagement, Bounty) sourced # from rivet-governance/public/disclosure-policy.md. Safe harbor is not # published until counsel confirms its wording; the repository SECURITY.md # cannot be linked because the repositories are private. # # OPEN (risk R-25): security@rivet.technology must exist and be monitored # before this file ships to production — a Contact: address that bounces is # worse than none. Confirm the mailbox, then close R-25 in the register. Contact: mailto:security@rivet.technology Expires: 2027-09-06T00:00:00.000Z Preferred-Languages: en Policy: https://rivet.technology/security#disclosure Canonical: https://rivet.technology/.well-known/security.txt