# StoneReason — how to report a security problem. # # There is no bug bounty and nothing here promises payment. What is promised is # that a report is read by somebody who can act on it, and answered. Contact: mailto:security@stonereason.com Contact: https://stonereason.com/security/ Expires: 2027-09-12T12:11:56Z Preferred-Languages: en Canonical: https://stonereason.com/.well-known/security.txt Policy: https://stonereason.com/security/ # What is most useful in a report: what you did, what happened, and the # `request_id` from the response if there was one. A request id is safe to # send. An API key secret is not, and is never needed to investigate anything.