# security.txt for baraa.sy - RFC 9116 # https://www.rfc-editor.org/rfc/rfc9116 Contact: mailto:me@baraa.sy Expires: 2027-03-01T00:00:00.000Z Canonical: https://baraa.sy/.well-known/security.txt Policy: https://baraa.sy/security-policy Preferred-Languages: en, ar Hiring: https://baraa.sy/hire-baraa # This is a personal portfolio site. It holds no customer data, takes # no payments, and has no bug bounty - there is no money here, for # anyone. Reproducible vulnerabilities are genuinely welcome and will # be fixed: XSS, injection, authentication or session flaws, exposed # secrets, access-control bypass. Send one and you will get a reply. # # Please do not send: raw scanner output nobody has verified by hand, # missing-header or TLS-grade findings, clickjacking on pages with no # sensitive action to hijack, CVSS scores with no working proof of # concept, or a request for payment in advance of a finding. Those # are closed unread. The full scope, the safe-harbour terms and the # disclosure timeline are at https://baraa.sy/security-policy.