# SparkStream vulnerability disclosure, in the machine-readable form (RFC 9116). # # This file is a signpost, not the policy. The policy is the page linked below, and # that page is the one that grants permission to test and says what we owe you back. # # Expires is mandatory and is checked on every build of this site: the build fails if # this file is missing, or if the date below is less than 30 days away. A disclosure # contact that has quietly gone stale is worse than not publishing one at all. # # api.sparkstreamapp.com/.well-known/security.txt redirects here, so there is exactly # one copy of this file and it cannot drift out of step with itself. # # Deliberately unsigned. RFC 9116 suggests an OpenPGP cleartext signature; we would # rather publish none than one backed by a key we do not reliably maintain, and this # file is served over HTTPS from the domain it describes. Ask if you want one. Contact: mailto:security@sparkstreamapp.com Expires: 2027-08-07T23:59:59.000Z Policy: https://sparkstreamapp.com/security Acknowledgments: https://sparkstreamapp.com/security/thanks Preferred-Languages: en Canonical: https://sparkstreamapp.com/.well-known/security.txt