# VIBSL vulnerability disclosure (RFC 9116) # Found a security issue in vibsl.com, app.vibsl.com, api.vibsl.com, # or a VIBSL-published artifact? Please tell us privately first. Contact: mailto:security@vibsl.com Expires: 2027-08-01T00:00:00.000Z Preferred-Languages: en Canonical: https://vibsl.com/.well-known/security.txt Policy: https://vibsl.com/security # We confirm receipt within 3 business days. No bug bounty program # exists yet; we credit reporters who want credit once a fix ships. # Reporting abuse hosted BY a customer ON the platform, such as a # phishing page on a vibsl.app subdomain, is a different job and goes # to abuse@vibsl.com. This file covers vulnerabilities IN VIBSL. The # distinction matters: a reporter who lands here after finding a # malicious customer site would otherwise read the scope line above # and conclude this is the wrong channel. # See https://vibsl.com/abuse