# Let's Consent — security.txt (RFC 9116) Contact: mailto:security@letsconsent.eu Expires: 2027-07-01T00:00:00.000Z Preferred-Languages: en, de Canonical: https://letsconsent.eu/.well-known/security.txt Policy: https://letsconsent.eu/compliance#disclosure # Vulnerability disclosure policy (summary — full text at the Policy URL): # # - Report suspected vulnerabilities to security@letsconsent.eu. # - We acknowledge reports within 5 business days and keep you informed # while we work on a fix. # - Good-faith research under this policy is welcome; we will not pursue # legal action for it (safe harbor). # - Please avoid accessing other users' data, degrading the service, or # social-engineering our operators. Use test accounts where possible. # - Allow us a 90-day remediation window before public disclosure. # - We credit reporters who wish to be credited. There is no bug bounty.