# Security contact for chordfrog.app and the ChordFrog iOS app. # Format: RFC 9116. https://www.rfc-editor.org/rfc/rfc9116 Contact: mailto:timo@skadi.chat Expires: 2027-08-20T00:00:00.000Z Preferred-Languages: en Canonical: https://chordfrog.app/.well-known/security.txt Canonical: https://chordfrog.app/security.txt Policy: https://chordfrog.app/agents/#safety # Scope # # In scope: chordfrog.app (a static site on Cloudflare Pages) and the ChordFrog # iOS app, including the chordfrog:// URL scheme documented at # https://chordfrog.app/agents/#url-scheme # # The safety rules for that scheme are contract and have tests pinning them. A # way to make a chordfrog:// URL destroy data, spend money, change a setting, or # write to a player's mastery record from a link is a real finding — please # report it. # # Out of scope: reports generated by automated scanners with no demonstrated # impact, missing headers on a site that serves no user data, and anything # concerning Google AdMob or Apple's App Store infrastructure, neither of which # is ours to fix. # # There is no bug bounty. There is a person who reads every message and replies.