# Forward March (forwardmarch.vet) — RFC 9116 vulnerability disclosure # contact. Backlog task-79. Served verbatim from web/public/** by Nitro's # static preset on both dev and prod (no per-stage templating — the # contact address and policy are the same regardless of which stage # served this file). Content-Type: text/plain is set automatically by the # deploy pipeline's `aws s3 sync` (same mechanism robots.txt already # relies on — file extension -> mimetype, no CDK/CloudFront change # needed; see backend/cdk/edge-stack.ts's SPA-fallback function, which # leaves any URI with a "." in its final path segment untouched at the # origin). # # Expires below is a real 1-year-out date, not a placeholder — an expired # security.txt is worse than none (RFC 9116 recommends short-lived # Expires precisely so stale contact info doesn't linger). See # docs/runbook.md's "security.txt renewal" section for the renewal # reminder; this file needs a new Expires date well before 2027-08-02 # (that date is UNCHANGED by backlog task-99 below — renewal stays # tracked separately in docs/runbook.md, not bumped as a side effect of # this contact-address change). # # Contact changed from devs@ to a dedicated security@ alias (backlog # task-99) only after backend/cdk/mail-routing-stack.ts's receipt rule # was updated to actually route security@forwardmarch.vet AND that was # proven with a genuinely external send/receive test (docs/runbook.md # §15) — never the other order, since publishing an address before it # routes would black-hole every report sent to it. Contact: mailto:security@forwardmarch.vet Expires: 2027-08-02T00:00:00.000Z Preferred-Languages: en Canonical: https://www.forwardmarch.vet/.well-known/security.txt Policy: https://www.forwardmarch.vet/security