# Credda security contact — RFC 9116 # # Researchers and automated scanners look for this file before emailing, and # enterprise security questionnaires increasingly ask whether one exists. # # THE EXPIRY IS NOT DECORATION. RFC 9116 requires it, and a file past its # Expires date is treated as stale and ignored — so this needs renewing. Set a # calendar reminder for a month before the date below; a lapsed security.txt is # worse than none, because it advertises a contact nobody is committing to. # # The address is a Google Workspace group whose members are deliberately few. # It accepts mail from outside credda.io and its archive is NOT externally # readable: a vulnerability report is the most sensitive mail Credda receives. Contact: mailto:security@credda.io Expires: 2027-08-01T00:00:00.000Z Preferred-Languages: en Canonical: https://credda.io/.well-known/security.txt Canonical: https://api.credda.io/.well-known/security.txt Policy: https://credda.io/security