# Vulnerability disclosure for MspCoreX — RFC 9116. # # Served statically from apps/web/public/.well-known/security.txt. Caddy has no # .well-known handler, so this falls through the catch-all to Next.js. # # ⚠ Expires is MANDATORY and this file is INVALID once it passes. Renew it # yearly; tests/meta/security-txt.test.ts fails 30 days before that date so the # reminder arrives while there is still time to act. Contact: mailto:security@mspcorex.com Expires: 2027-09-01T00:00:00.000Z Preferred-Languages: en, ro Canonical: https://app.mspcorex.com/.well-known/security.txt