# Security contact for calik.io, per RFC 9116 # # If you have found a vulnerability, this is where to send it. Reports are # welcome from anyone; there is no bounty, but there is a reply. # # Please include enough to reproduce it, and please do not test against other # people's accounts or payment records. A proof of concept against your own is # enough to make the point. Contact: mailto:support@calik.io Expires: 2027-08-19T00:00:00.000Z Preferred-Languages: en, tr Canonical: https://calik.io/.well-known/security.txt # Out of scope, because they are known and deliberate: # - The admin panel reachable at #admin on the marketing site. It edits # localStorage in your own browser and calls nothing on the server; the # password in front of it is a convenience, not a boundary. # - Rate limits reported as "missing" on endpoints that have them per IP.