# Flypify — security contact, per RFC 9116. # # If you have found a vulnerability, write to the address below. The full # policy — scope, what we ask while you test, and what you get back — is at # https://flypify.com/security # # ⚠ Expires below is a real deadline, not decoration (RFC 9116 §2.5.5): past # that date this file is invalid and reads as an abandoned channel. Renewing it # means re-checking that the address still reaches a person, not just editing # the date. web/lib/securityTxt.test.ts goes red when it lapses. # # ⛔ 2026-08-22 — Contact used to be the "security@" address on this domain, a # mailbox that does not exist. An unreachable Contact is the same failure as a # lapsed Expires, and this file is harder to notice than the page: nothing # renders it, so it rots unread. It must always name the same address as # /security, which is why web/lib/publishedLegalTerms.test.ts now reads this # file and that page together and fails if they disagree. (The dead address is # deliberately not spelled out here: that test sweeps this file whole, and a # historical note carrying the literal string would be a permanent false hit.) Contact: mailto:mikail@flypify.com Contact: https://flypify.com/security Expires: 2027-08-01T00:00:00.000Z Preferred-Languages: en Policy: https://flypify.com/security Canonical: https://flypify.com/.well-known/security.txt