# Hardtack — Vulnerability Disclosure Program (VDP) # # This file follows the RFC 9116 (security.txt) standard. # See https://www.rfc-editor.org/rfc/rfc9116 for the spec. # Full policy + scope: https://hardtack.ai/security Contact: mailto:security@hardtack.ai Expires: 2027-05-16T00:00:00.000Z Preferred-Languages: en Canonical: https://hardtack.ai/.well-known/security.txt Policy: https://hardtack.ai/security # SLA (from the published policy): # Acknowledgement: within 72 hours (Mon-Fri). # Triage decision: within 7 days of acknowledgement. # Fix or mitigation: within 30 days of an accepted finding. # # This is a VDP, NOT a bug bounty — Hardtack does not currently pay # financial rewards. Credible reports get a personal acknowledgement # and credit (with researcher permission) in the post-fix advisory.