# Bubl Cloud B.V. security policy # https://bublcloud.com # # Carried over from legacy/src/.well-known/security.txt with the three URLs re-pointed at this host. # # **The hostname is not cosmetic here.** RFC 9116 requires the `Canonical` field to be the URI the # file is actually served from; a file whose Canonical names a different host is to be treated as # invalid, so the whole policy is ignored, which is worse than not publishing one, because it looks # published. `gate:origin` caught the copied version on the first run, and again when the phase 1 # asset copy overwrote this file with the legacy one. # # When bubl.cloud is forwarded here (docs/VPS-DEPLOY.md#the-hostnames), add a second `Canonical` line # for it. RFC 9116 permits several, and both hosts will genuinely serve this file. # # Everything that is content is unchanged: the addresses, the languages, the expiry, the policy page. # See docs/PARITY.md on why a URL is not copy. Contact: mailto:security@bubl.cloud Contact: mailto:contact@bubl.cloud Contact: https://bublcloud.com/contact/ Expires: 2027-04-23T00:00:00.000Z Preferred-Languages: en, nl Canonical: https://bublcloud.com/.well-known/security.txt Policy: https://bublcloud.com/responsible-disclosure/