# BreachLine Labs Limited — vulnerability disclosure # RFC 9116. Full policy, scope and safe-harbour terms: https://breachline.io/security # # Expires is REQUIRED and RFC 9116 recommends LESS THAN a year out — exactly 365 days sits on the # boundary and some validators flag it. Renew before the date below or scanners will treat this file # as stale and the contact as unverified. # # Only ONE Contact is listed: a URI Contact is meant to be a submission form, and /security is a # policy page with no form, so a second entry pointing at it duplicated Policy and told a scanner # nothing new. Contact: mailto:security@breachline.io Expires: 2027-06-30T00:00:00.000Z Policy: https://breachline.io/security Preferred-Languages: en Canonical: https://breachline.io/.well-known/security.txt # We build offensive-security tooling and welcome coordinated disclosure. # Please give us a reasonable window to remediate before any public disclosure, # and do not run automated scanners against production beyond what is needed to # demonstrate an issue. Scope, exclusions and our safe-harbour commitment under # the Computer Misuse Act 1990 are set out in full at https://breachline.io/security