# Security contact for hellocloudwatch.com — RFC 9116. # # ⚠️ `Expires:` IS MANDATORY, AND THIS FILE'S EXPIRY IS A SCHEDULED CI RED. # `apps/website/scripts/check-built-head.mjs` fails the deploy once the date # below is in the past, because an expired security.txt is an INVALID one and # a disclosure address nobody maintains is worse than none. That is deliberate, # and the fix is ONE value: bump `Expires:` below and in the byte-identical # copy at `apps/website/static/security.txt`. The two files are compared for # byte-equality by the same checker, so change both or it stays red. # # ⚠️ COPY, DO NOT SYMLINK. `adapter-static` copies `static/` into `build-swa/`; # a symlink does not survive that reliably. This is the same call 15-02 made # for the vendor logos. Contact: mailto:security@hellocloudwatch.com Expires: 2027-09-01T00:00:00.000Z Preferred-Languages: en Canonical: https://hellocloudwatch.com/.well-known/security.txt