# Signoos vulnerability disclosure policy (RFC 9116) # # If you believe you have found a security issue in Signoos — the web # application, the API, the CLI (@signoos/cli) or the MCP server # (@signoos/mcp) — please tell us using the contact below. Contact: mailto:security@signoos.com Expires: 2027-08-07T00:00:00.000Z Preferred-Languages: en Canonical: https://signoos.com/.well-known/security.txt Policy: https://signoos.com/.well-known/security.txt # What helps us act quickly # # - The affected component and version (for the CLI: `signoos --version`). # - Steps to reproduce, or a proof of concept. # - What an attacker gains, and any preconditions they need. # # What to expect # # - We acknowledge reports and will tell you what we find, including when we # conclude an issue is not exploitable and why. # - Please give us reasonable time to remediate before public disclosure. # # Out of scope # # - Findings that require access to a user's own machine or account. # - Reports produced solely by automated scanners with no demonstrated impact. # - Denial of service through traffic volume alone. # # Please do not access, modify or exfiltrate data belonging to anyone other # than yourself, and do not run tests that degrade service for other users.