# RFC 9116 — security.txt for https://defenz.org # DEFENZ — Cameroon bug-bounty platform. This file tells security # researchers how to disclose a vulnerability safely, what the safe-harbor # scope is, and how long coordinated disclosure takes. Contact: mailto:security@defenz.org Contact: https://defenz.org/fr/security/disclosure Encryption: https://defenz.org/.well-known/pgp-key.asc Expires: 2027-12-31T23:59:59Z Preferred-Languages: fr, en Canonical: https://defenz.org/.well-known/security.txt Policy: https://defenz.org/fr/security/disclosure Policy: https://defenz.org/en/security/disclosure Acknowledgments: https://defenz.org/fr/hall-of-fame Hiring: https://defenz.org/fr/contact # Scope: the same assets listed in our /fr/programs directory. Anything # outside that scope is OUT OF SCOPE — no safe harbor, no bounty. # As of 2026-10-06 the live programme is "DEFENZ — Bug bounty de la # plateforme defenz.org" covering defenz.org, www.defenz.org, api.defenz.org # (and the matching subdomains as listed on the programme page). # Forbidden targets (always OUT OF SCOPE, anywhere on our zones): # • Social-engineering our staff (phishing, vishing, physical intrusion). # • Denial-of-service / volumetric load testing. # • Spamming our inbound channels with duplicate or low-effort reports. # • Accessing, modifying or retaining user data beyond the minimum # needed to demonstrate the vulnerability. # • Any third-party service we use (Clerk, Cloudflare, R2, MTN MoMo, # Orange Money) — disclose upstream to the vendor instead. # Co-ordinated disclosure: 90 days from acknowledgement, extendable on # request. Critical P1 findings page within 24 hours. Public disclosure # only after a fix is shipped OR after the 90-day window expires.