# Turtini security contact and vulnerability-disclosure policy (RFC 9116). # # Turtini operates a RESPONSIBLE-DISCLOSURE program, NOT a paid bug-bounty # program. We do NOT offer monetary rewards, bounties, or any other # compensation for vulnerability reports, and submitting a report does not # create any expectation of payment. We review genuine, reproducible, original # findings in good faith and will credit reporters on request. # # Automated-scanner "beg bounty" reports (missing headers, clickjacking on pages # with no state-changing actions, generic OAuth/CSRF/rate-limit templates, email # enumeration, and similar low-severity or non-issues) are not eligible and may # not receive an individual response. Contact: mailto:security@turtini.com Policy: https://turtini.com/security Preferred-Languages: en Canonical: https://turtini.com/.well-known/security.txt Expires: 2027-08-04T00:00:00.000Z