# AlecRae Security Policy # RFC 9116: https://www.rfc-editor.org/rfc/rfc9116 # # We take security seriously. If you believe you have discovered a # vulnerability, please report it responsibly using the contacts below. # We commit to acknowledging reports within 2 business days and to # coordinated disclosure with all researchers acting in good faith. Contact: mailto:security@alecrae.com Contact: https://alecrae.com/security Expires: 2027-04-16T00:00:00.000Z Encryption: https://alecrae.com/.well-known/pgp-key.txt Preferred-Languages: en Canonical: https://alecrae.com/.well-known/security.txt Policy: https://alecrae.com/security # Hiring and Acknowledgments fields were removed 2026-08-29. They pointed at # https://alecrae.com/careers and https://alecrae.com/security/hall-of-fame, # and neither route exists — both answered 404. A security.txt that sends a # researcher to a dead URL is worse than one that omits the field: RFC 9116 # fields are advertised capabilities, and an advertised capability that is # not there is the same class of defect as an advertised STARTTLS that does # not handshake. They return here when the pages do. # Scope: *.alecrae.com, the AlecRae mobile and desktop apps, and the # AlecRae public API. Out of scope: social engineering, physical security, # denial-of-service, issues requiring privileged network position, # third-party services we do not operate. # # Safe harbor: Good-faith security research that follows this policy # will not be pursued under the Computer Fraud and Abuse Act, the # Digital Millennium Copyright Act, or similar laws. See # https://alecrae.com/security for full safe-harbor terms.