# SendBeam — how to report a security problem. # Format: RFC 9116 (https://www.rfc-editor.org/rfc/rfc9116). # Our full vulnerability disclosure policy is the Policy link below; it is # what governs, including scope, safe harbour and our response timescales. # Contacts, most preferred first. Contact: mailto:security@sendbeam.io Contact: https://sendbeam.io/contact?s=security Policy: https://sendbeam.io/legal/security Preferred-Languages: en Canonical: https://sendbeam.io/.well-known/security.txt Expires: 2027-09-01T00:00:00.000Z # We acknowledge every report within one working day, assess it within five, # and update you at least fortnightly until it is closed. We do not pay a # bounty, and we say so on the policy page rather than leave you guessing. # We credit reporters who want it. Please do not access, change or keep # anyone else's data while you are looking, and give us ninety days before # you publish.