# Avano — security contact (RFC 9116) # # Until this file existed, https://avano.app/.well-known/security.txt returned # HTTP 200 serving the homepage, because Cloudflare Pages falls back to index.html # for any missing path. A researcher's tooling saw a 200 with HTML in it, which # reads as a malformed file rather than an absent one — worse than a clean 404. # # The address below is the one already published on the homepage and in use. # A dedicated security@avano.app is published on the brand page but the mailbox # is not confirmed to exist, so it is deliberately NOT listed here: a disclosure # channel that silently drops mail is worse than no channel, because the # researcher believes they have reported it. Contact: mailto:hello@avano.app Expires: 2027-07-27T00:00:00.000Z Preferred-Languages: en, ro Canonical: https://avano.app/.well-known/security.txt # We have no bug bounty and no PGP key published yet. Say so rather than imply # otherwise. If you have found something that affects users, mail the address # above and we will reply; if you need encrypted contact before disclosing, # ask for a key in that first mail. # # What we most want to hear about: anything that links two conversing users, # anything that reveals that a conversation happened at all, anything that # survives "delete identity", and anything that reaches a signed release.