# CyberGoBag security.txt — RFC 9116 # Last reviewed: 2026-04-26 Contact: mailto:security@cybergobag.com Expires: 2027-04-26T00:00:00Z Preferred-Languages: en Canonical: https://cybergobag.com/.well-known/security.txt Policy: https://cybergobag.com/trust # Reporting guidance # - Report any suspected vulnerability to security@cybergobag.com. # - We acknowledge credible reports within one business day. # - We follow a 90-day coordinated disclosure window. # - Do not test against production tenants you do not control. # - Researchers acting in good faith and within scope will not be pursued # under the Australian Cybercrime Act or equivalent legislation. # Out of scope # - Denial-of-service / volumetric attacks # - Social engineering of staff or customers # - Physical testing of any premises # - Automated scanner output without a working proof of concept