# Keyway — security contact (RFC 9116) # # If you have found a vulnerability, we want to hear about it and we will not # take legal action against good-faith research. Please give us a reasonable # window to fix an issue before disclosing it publicly. # # In scope: subtounlock.app and its API. # Out of scope: findings that require physical access, social engineering of # our staff, or denial of service — please do not test availability. # # Expires must be refreshed annually. A stale security.txt is treated as # invalid by scanners and by most researchers. Contact: mailto:security@subtounlock.app Expires: 2027-08-12T00:00:00.000Z Preferred-Languages: en, vi Canonical: https://subtounlock.app/.well-known/security.txt Policy: https://subtounlock.app/safety