# Hobbstack security contact — RFC 9116 # # Beta mega-audit L4-006: /security offered the (broken) contact form as # the ONLY vulnerability-disclosure channel, published no email address # anywhere on the page, and /.well-known/security.txt returned 404 — so a # researcher had no working way to report anything. # # support@hobbstack.com is used deliberately: it is the address the site # already routes to (contact page mailto card), so it is known-good. # Prefix the subject with "SECURITY" and it gets triaged accordingly. Contact: mailto:support@hobbstack.com Contact: https://www.hobbstack.com/contact?topic=security Expires: 2027-08-03T00:00:00.000Z Preferred-Languages: en Canonical: https://www.hobbstack.com/.well-known/security.txt # Beta mega-audit rev-landing LOW-1: this file used to declare # Policy: https://www.hobbstack.com/security # RFC 9116 section 2.5.7 defines "Policy" as the URI of the vulnerability # DISCLOSURE POLICY — scope, safe harbour, expected response time. # /security is a security-practices page with a reporting contact block; # it states none of those three, so pointing "Policy" at it promised more # than the linked page delivers. No formal disclosure policy is published # yet, so the field is omitted rather than overclaimed (it is optional). # Restore the line only once /security (or a dedicated page) actually # carries scope + safe-harbour + response-time language. # # Security practices, and the reporting contact block, are here: # https://www.hobbstack.com/security