# ROLearn security contact, per RFC 9116. # # Canonical location: https://rolearn.dev/.well-known/security.txt # Served straight off the CRA build output by nginx's `location /` # (try_files matches the real file before the SPA index.html fallback), # so it needs no backend route. # # Expires is MANDATORY under RFC 9116 and a stale value makes the whole # file untrustworthy to a scanner. Keep it under a year out and renew it # on the same pass that reviews the disclosure policy at /trust. Contact: mailto:security@rolearn.dev Expires: 2027-09-01T00:00:00.000Z Preferred-Languages: en Canonical: https://rolearn.dev/.well-known/security.txt Policy: https://rolearn.dev/trust