# Stattio — Vulnerability Disclosure Policy # https://stattio.io/.well-known/security.txt # RFC 9116 compliant Contact: mailto:security@stattio.io Expires: 2028-05-06T00:00:00.000Z Preferred-Languages: sr, en Canonical: https://stattio.io/.well-known/security.txt Encryption: https://stattio.io/.well-known/pgp-key.txt # PGP Key Fingerprint: 1DEA F652 8D07 424D 5950 C217 3938 3100 83C0 FC46 # Key type: Ed25519 / Curve25519 — expires 2028-05-06 # Scope # In-scope: stattio.io and all subdomains, Stattio iOS/Android apps (when released) # Out-of-scope: Third-party services (Supabase, Mux, Vercel infrastructure) # We commit to: # - Acknowledge receipt within 48 hours # - Provide a status update within 7 days # - Fix confirmed vulnerabilities within 90 days (P1: 7 days, P2: 30 days) # - Not pursue legal action against good-faith researchers # Please include: # - Description of the vulnerability # - Steps to reproduce # - Potential impact assessment # - Your contact information (optional — anonymous reports accepted) Policy: https://stattio.io/security # No `Hiring:` field. It pointed at https://stattio.io/careers, which does not # exist — measured 2026-08-21: 307 to /login, because an absent route falls # through to the auth gate. RFC 9116 makes the field optional, and a security # policy that ships one dead link is the wrong first impression for the people # who read this file.