# MAFATE — security disclosure policy (RFC 9116) # https://www.mafate.io/.well-known/security.txt Contact: mailto:security@mafate.io Expires: 2027-05-28T00:00:00.000Z Preferred-Languages: fr, en Canonical: https://www.mafate.io/.well-known/security.txt Policy: https://www.mafate.io/legal/security-policy # ⛔ `Hiring:` retiré le 10/08/2026 : il annonçait https://www.mafate.io/careers, qui répond 404. # Un champ RFC 9116 qui pointe dans le vide décrédibilise les autres, à commencer par `Policy:`. # Il reviendra le jour où la page existera. # Acknowledgments page (to be populated): # Acknowledgments: https://www.mafate.io/security/acknowledgments # Reporting guidelines: # - For vulnerabilities, email security@mafate.io with reproduction steps. # - PGP-encrypted reports welcome (key publication pending). # - We commit to acknowledging reports within 72h and providing status updates # on a regular basis. # - Coordinated disclosure timeline: 90 days standard, negotiable for critical # vulnerabilities affecting customer data.