# Security contact for PuglieseWeb LTD (company no. 17078772), covering # www.puglieseweb.com, the products it links to, and EmaIngestBot. # # Safe harbour. If you find a flaw in good faith and stay within the policy # below, we will not report you to law enforcement and we will not bring a # civil claim against you for the access or testing that produced the finding. # This undertaking is the point of the file: the UK has no research defence to # the Computer Misuse Act 1990, so unauthorised access is an offence under s.1 # whatever the finder's motive, and without an express permission a researcher # who tells us about a flaw has confessed to one. Silence would be their # rational move, and we would never learn about the flaw. # # In return: test only against your own account or an account you have # permission to test; do not access, alter or extract data that is not yours; # do not degrade the service for other users; report privately, and give us a # reasonable period to fix the issue before you publish. # # Those five conditions are the conditions in section 9 of the policy page # below, and nothing more. They are kept identical on purpose: a file that # attaches even one extra condition turns a researcher who did exactly what the # page asked into someone outside the undertaking, which is the opposite of # what a safe harbour is for. Change one, change both. # # ASCII only, deliberately. RFC 9116 requires this file to be served as # "text/plain; charset=utf-8"; the deploy pipeline uploads .txt and lets the # AWS CLI guess the type, which yields text/plain with no charset parameter, so # any non-ASCII byte here would be decoded according to the reader's default. Contact: mailto:security@puglieseweb.com Expires: 2027-09-03T00:00:00.000Z Preferred-Languages: en, it Canonical: https://www.puglieseweb.com/.well-known/security.txt Policy: https://www.puglieseweb.com/trust