# Outstation — https://outstation.dev # # One address reaches a person for vulnerabilities, relay abuse and copyright # notices alike. The full policy, including scope and what to expect, is at # https://outstation.dev/security # # The contact is on quirl.co rather than outstation.dev, and that is deliberate # rather than a mistake to report: Quirl L.L.C. is the entity behind Outstation # and the name on the installer's Developer ID signature. A researcher who has # just verified that signature is looking at the same name here. # # Expires is a commitment, not a formality: RFC 9116 asks for a date under a # year out so that a stale file is detectable rather than merely old. Renewing # it means re-reading the policy, which is the point. Contact: mailto:security@quirl.co Expires: 2027-08-01T00:00:00.000Z Preferred-Languages: en Canonical: https://outstation.dev/.well-known/security.txt Policy: https://outstation.dev/security