Contact: security@devilinabox.be Expires: 2025-12-31T23:59:59.000Z Acknowledgments: https://devilinabox.be/security Preferred-Languages: en, nl Canonical: https://devilinabox.replit.app/.well-known/security.txt # Security Policy for Devil in a Box This file describes our security practices and how to report vulnerabilities. ## Reporting Security Issues If you discover a security vulnerability, please send an email to security@devilinabox.be with: - A description of the vulnerability - Steps to reproduce the issue - Your contact information We take all security reports seriously and will respond promptly. ## Security Measures - All external links use rel="noopener noreferrer" - Content Security Policy (CSP) implemented - Rate limiting on API endpoints - Input validation and sanitization - HTTPS enforced in production - Security headers configured ## Bug Bounty We currently do not offer a formal bug bounty program but appreciate responsible disclosure.