# Strazh / Graphenlabs security disclosure policy — RFC 9116. # Served as a static file (public/.well-known/security.txt) rather than a # generated App Router route: the format is fixed plaintext, there's no # per-request data to compute, and .txt isn't in middleware.ts's matcher # exclusion list so this still needs a post-deploy `curl -I` sanity check # even though clerkMiddleware() itself is a no-op for this path. Contact: mailto:security@graphenlabs.com Expires: 2027-08-03T00:00:00.000Z Preferred-Languages: en Canonical: https://strazh.graphenlabs.com/.well-known/security.txt