# Complyology vulnerability disclosure # A compliance platform that cannot take a security report is a contradiction. Contact: mailto:security@complyology.io Expires: 2027-08-28T00:00:00.000Z Preferred-Languages: en Canonical: https://complyology.io/.well-known/security.txt Policy: https://complyology.io/.well-known/security.txt # Expires is REQUIRED by RFC 9116 — a security.txt without it is invalid and # gets flagged by scanners. Refresh this date at least annually; an expired # file tells a researcher the channel is abandoned. # We do not run a paid bounty. We do read every report, we respond, and we # credit reporters who want credit. Please give us a reasonable window to ship # a fix before disclosing publicly. # Please do not send us CUI, evidence files, or exports from a live assessment # as part of a report. Redact first — we are not a cloud service provider for # your covered defense information and do not want to become one.