# RFC 9116 security contact (external audit 2026-07-28, finding 8). # # Without this file, a researcher who finds something has no address to send it # to and it ends up on social media instead. Served unauthenticated on purpose: # lib/site-gate.ts exempts this path, because a security contact that sits # behind the beta password is a security contact nobody can reach. # # OPERATOR: Expires is a hard requirement of RFC 9116 and scanners treat an # elapsed date as an invalid file. Refresh it before 2027-09-13. Also confirm # security@grailswap.io actually delivers. DMARC exists since 2026-08 (p=none # — monitoring only); tighten toward quarantine once legitimate mail is proven. Contact: mailto:security@grailswap.io Expires: 2027-09-13T00:00:00.000Z Preferred-Languages: en Canonical: https://www.grailswap.io/.well-known/security.txt Policy: https://www.grailswap.io/terms