# Spacealyx — security contact information. # # Format: RFC 9116 ("A File Format to Aid in Security Researcher Engagement"). # Human-readable policy, in English and Spanish: https://apps.spacealyx.com/security # # WRITTEN 2026-08-02. Authority for the dates and obligations behind this file: # docs/SECURITY-HORIZON-2026-2027.md §3.1 — Cyber Resilience Act (Regulation (EU) 2024/2847) # Annex I Part II point (5), a coordinated vulnerability disclosure policy, and point (6), a # published contact address for reports. Article 14 reporting applies from 11 September 2026 and # Article 69(3) carves it out of the grandfathering in 69(2), so it binds from the first EU sale # regardless of when the product was placed on the market. # # --------------------------------------------------------------------------------------------- # THIS FILE IS NOT SIGNED, AND IT SHOULD BE. # # RFC 9116 §2.3 RECOMMENDS that security.txt be digitally signed with an OpenPGP cleartext # signature, so that a reader can tell this file from one injected by whoever last compromised the # host — which is precisely the situation in which somebody reads it. It is unsigned because this # company has no published OpenPGP key yet, and a signature from a key nobody can find is # decoration. When that key exists, this file gains a cleartext signature and an `Encryption:` # field pointing at the key, in the same change. Tracked: docs/PENDING.md § REGULATORY, item R3. # # The same gap is stated in plain language on /security rather than hidden here, because a # reporter deciding whether to send us an exploit in clear text deserves to know before they send # it, not after. # --------------------------------------------------------------------------------------------- # # CANONICAL, AND ONE KNOWN MISMATCH. The URI below is where this file belongs and where # astro.config.mjs already points every canonical link on the site. The custom domain is not # attached yet (docs/PENDING.md §1), so until it is, this file answers on the project's # *.pages.dev host and a strict reader comparing the serving URI against `Canonical:` will see a # mismatch. That is a deployment step, not a defect in this file, and it resolves itself the day # the domain is attached. Do not "fix" it by pointing Canonical at the pages.dev host — that # hostname is being blocked deliberately (PENDING D2). # # EXPIRES. RFC 9116 §2.5.5 requires exactly one Expires field and recommends less than a year out. # 30 June 2027 is chosen so the review falls BEFORE the 11 December 2027 CRA full-compliance date # rather than in the middle of it — when this file is revisited, the CE marking, the declaration # of conformity and the declared support period are all on the same desk. # An expired security.txt is worse than none: it tells a researcher the address is stale and that # nobody is home. `tests/security-policy.test.ts` fails the build once this date is inside 60 days. Contact: mailto:megasent.go@gmail.com Expires: 2027-06-30T23:59:59.000Z Preferred-Languages: en, es Canonical: https://apps.spacealyx.com/.well-known/security.txt Policy: https://apps.spacealyx.com/security