# Vulnerability disclosure for bandura.dev and the Bandura desktop app. # Format: RFC 9116. Human-readable version: https://bandura.dev/security/ # # Expires must stay in the future or this file is invalid by the spec, so it is # reviewed at every release. See apps/website/src/pages/security.astro. Contact: mailto:hello@bandura.dev Expires: 2027-08-08T00:00:00.000Z Preferred-Languages: en, uk Canonical: https://bandura.dev/.well-known/security.txt Policy: https://bandura.dev/security/ # What to expect: a human acknowledgement within three working days, from the # person who wrote the code. Please give us a reasonable window to ship a fix # before publishing. Credit in the release notes unless you would rather not. # # There is no bug bounty. Bandura is built by one person and there is no budget # for one, and saying so is better than leaving you to find out after the work.