# AlecRae Security Policy # RFC 9116: https://www.rfc-editor.org/rfc/rfc9116 # # We take security seriously. If you believe you have discovered a # vulnerability, please report it responsibly using the contacts below. # We commit to acknowledging reports within 2 business days and to # coordinated disclosure with all researchers acting in good faith. Contact: mailto:security@alecrae.com Contact: https://alecrae.com/security Expires: 2027-04-16T00:00:00.000Z Encryption: https://alecrae.com/.well-known/pgp-key.txt Preferred-Languages: en Canonical: https://alecrae.com/.well-known/security.txt Policy: https://alecrae.com/security Hiring: https://alecrae.com/careers Acknowledgments: https://alecrae.com/security/hall-of-fame # Scope: *.alecrae.com, the AlecRae mobile and desktop apps, and the # AlecRae public API. Out of scope: social engineering, physical security, # denial-of-service, issues requiring privileged network position, # third-party services we do not operate. # # Safe harbor: Good-faith security research that follows this policy # will not be pursued under the Computer Fraud and Abuse Act, the # Digital Millennium Copyright Act, or similar laws. See # https://alecrae.com/security for full safe-harbor terms.