# AarMe — security.txt (RFC 9116) # # Separate from the cyberaar.io file because Policy and Canonical differ: a # researcher landing on aarme.cyberaar.io needs the AarMe programme rules, not # the corporate disclosure page. # # The reason this file exists at all is narrow and worth recording. Cloudflare's # email address obfuscation is enabled on the zone, so every address rendered in # HTML reads "[email protected]" to a visitor without JavaScript. That is a # deliberate trade, accepted for anti-harvesting. But it left aarme.cyberaar.io # with no readable contact anywhere for such a visitor, on a bug bounty platform # whose audience disables scripts more than most. Cloudflare only rewrites HTML, # never a text file, so this is the fallback channel that survives the setting. # # Written AFTER the AarMe sync, which runs with delete:true and would otherwise # remove it. Contact: mailto:security@cyberaar.io Expires: 2027-08-31T15:58:09Z Preferred-Languages: fr, en Canonical: https://aarme.cyberaar.io/.well-known/security.txt Canonical: https://cyberaar.io/.well-known/security.txt Policy: https://aarme.cyberaar.io/regles/ Acknowledgments: https://aarme.cyberaar.io/palmares/