# https://evaluation.ee/.well-known/security.txt # # RFC 9116. Not an SEO file and no crawler reads it: it tells somebody who has # found a vulnerability where to send it, rather than leaving them to guess # between a contact form, a LinkedIn message and a public post. # # info@ is the address we already publish, so it is the one that is certainly # read - a security@ alias would be the convention, but a contact here that # bounces is worse than none. Point this at security@ once that mailbox exists. # # Expires is REQUIRED by the RFC and this file goes stale on that date - an # expired security.txt is reported as expired by every scanner that reads it, # which is worse than not publishing one. Move the date when you renew it, and # keep it under a year out. # # Apex only, deliberately. app. and api. are separate vhosts and would each # need their own copy; the apex is what scanners and researchers check first. Contact: mailto:info@evaluation.ee Expires: 2027-09-01T00:00:00Z Preferred-Languages: et, en Canonical: https://evaluation.ee/.well-known/security.txt