# security.txt — RFC 9116 # https://straightsum.com/.well-known/security.txt # # Referenced from https://straightsum.com/legal/security/, where its absence # was a broken link on the page describing responsible disclosure. Contact: mailto:security@straightsum.com Contact: https://straightsum.com/contacts/ # MUST be a future date. Review and extend annually — an expired file is # treated as invalid by scanners and by researchers. Expires: 2027-07-25T00:00:00.000Z Preferred-Languages: en Canonical: https://straightsum.com/.well-known/security.txt Policy: https://straightsum.com/legal/security/ # --------------------------------------------------------------------------- # Scope # # In scope: # straightsum.com and its subdomains # # Out of scope — these are operated by independent third parties. Report # issues to them directly; we cannot act on their infrastructure: # cdn101.zeroparallel.com (loan request form) # ccpa.lendyou.com (privacy request intake) # # Please do not: # - access, modify, or exfiltrate data belonging to anyone else # - run automated scanning that degrades availability for users # - submit real personal or financial information while testing # - engage in social engineering against staff or partners # # We acknowledge reports within 24 business hours and aim to resolve confirmed # issues within 90 days. We do not currently operate a paid bounty, but we # credit researchers who ask to be credited. # ---------------------------------------------------------------------------