# MAS Pilot — Responsible Disclosure Policy # https://securitytxt.org/ Contact: mailto:info@maspilot.io Contact: https://maspilot.io/security Expires: 2027-04-13T00:00:00.000Z Preferred-Languages: en Canonical: https://maspilot.io/.well-known/security.txt Policy: https://maspilot.io/security Hiring: https://maspilot.io/about # Scope # In-scope: maspilot.io, www.maspilot.io, and any first-party subdomain owned by # MAS Pilot LLC. The marketing site is a static Cloudflare Pages deployment. # # Out of scope: Google Forms endpoints used for the current waitlist, Cloudflare # infrastructure, Cloudflare Email Protection (/cdn-cgi/*), and any third-party # service not owned by MAS Pilot LLC. # Safe harbor # Good-faith security research conducted under this policy — with no data # destruction, social engineering, DoS, spam, or targeting of individual users — # will not be pursued legally. We will acknowledge reports within 3 business days.