# Campyon vulnerability disclosure (RFC 9116) # # Found a security issue in campyon.ai or the Campyon application? Mail the # contact below with enough detail to reproduce it. We acknowledge reports # within two business days. Please give us a chance to ship a fix before you # publish, and don't run tests that degrade the service or touch data # belonging to another workspace. # # Expires is a hard requirement of RFC 9116 and has to stay under a year out, # so this file needs a manual bump every year or researchers will read it as # abandoned. The reminder lives in docs/OPERATIONS.md. # # This is a static file rather than a route, so the two absolute URLs below # pin the host instead of deriving it from src/lib/site.ts, the way # indexnow.ts and the Deno edge functions also pin it. That's deliberate here: # Canonical and Policy have to name the production origin, so a preview # deployment advertising its own preview host would be wrong. Contact: mailto:security@campyon.ai Expires: 2027-08-01T00:00:00.000Z Preferred-Languages: en Canonical: https://campyon.ai/.well-known/security.txt Policy: https://campyon.ai/privacy#security