# SalaryLabs security.txt — RFC 9116 disclosure policy # # Purpose: tell security researchers how to disclose vulnerabilities to us # responsibly. We commit to: # - Acknowledge within 5 business days # - Triage within 10 business days # - Fix high/critical issues within 30 days # - Credit reporters in our Hall of Fame (if requested) # # Standard: https://datatracker.ietf.org/doc/html/rfc9116 Contact: mailto:security@salarylabs.site Contact: https://salarylabs.site/security/ Expires: 2027-12-31T23:59:59Z Preferred-Languages: en Canonical: https://salarylabs.site/.well-known/security.txt # Cryptographic key for signing disclosure-related messages (rotated yearly) # Use to encrypt sensitive PoC attachments when emailing. Encryption: https://salarylabs.site/.well-known/security-key.asc # Security acknowledgments — researchers who helped us ship fixes Acknowledgments: https://salarylabs.site/security/acknowledgments/ # Scope — what's in scope for this disclosure program # (any subdomain of salarylabs.site, all calculator endpoints, admin pages # behind authentication, public API endpoints, embed SDK, Cloudflare Workers) Hiring: https://salarylabs.site/security/careers/ # We follow coordinated disclosure — please don't go public until # we ship a fix or agree to a disclosure timeline. Preferred-Languages: en Policy: https://salarylabs.site/security/policy/