# Scoreflection — security contact (RFC 9116) # # If you have found a vulnerability in the Scoreflection app, API # (api.scoreflection.com), community forum (community.scoreflection.com) or this # site, please tell us through the channel below. We are a very small team and # will confirm receipt before doing anything else. # # The full policy — what to send, what we commit to in return, the 90-day # disclosure window and the good-faith safe harbour — is at # https://scoreflection.com/security.html, which is also where the Cyber # Resilience Act information lives (support period, updates, SBOM). # # Please do not run automated scanners against the API — the OMR transcription # endpoint is CPU-bound and rate-limited, and load is indistinguishable from # abuse from where we sit. If you need to demonstrate something at volume, ask # first and we will arrange a window. # # For anything involving the safety of a child, use the child-safety contact on # https://scoreflection.com/child-safety.html instead — it is read on a # different schedule. Contact: https://scoreflection.com/contact.html Expires: 2027-08-13T00:00:00.000Z Preferred-Languages: en, de Canonical: https://scoreflection.com/.well-known/security.txt Policy: https://scoreflection.com/security.html # EDIT: replace the Contact line with a dedicated mailbox # (mailto:security@scoreflection.com) once it exists and is monitored, and put # the same address on contact.html. A published contact that bounces is worse # than no file at all, which is why this points at the site's own contact page # rather than naming an address that does not yet receive mail. # # EDIT: Expires is one year out and is a hard requirement of RFC 9116 — an # expired file is treated as invalid. Renew it during the monthly dependency # audit (tools/audit_dependencies.ps1 in the server repo) so it never lapses.