# Paperwrist — security disclosure # RFC 9116 — https://datatracker.ietf.org/doc/rfc9116/ # # Report any security issue to the address below. Plain-text email is # preferred — there is no HackerOne / Bugcrowd programme. We aim to # acknowledge within 2 business days and to credit reporters in the # disclosure unless they ask to stay anonymous. # # There is no separate vulnerability-disclosure policy document, so this # file carries no Policy: field — the paragraph above IS the policy, and # pointing Policy: at the privacy policy would send a reporter somewhere # that says nothing about disclosure. # # In scope: this website, and the Paperwrist iOS / watchOS / Android / # Wear OS apps. Note the apps have no backend and no network code at # all, so "server-side" findings are almost certainly not ours. Contact: mailto:privacy@paperwrist.app Expires: 2027-06-30T23:59:59Z Preferred-Languages: en, es Canonical: https://paperwrist.app/.well-known/security.txt