# Security Policy for Project Pak-LLM (pak-llm.com) # Compliant with RFC 9116 — https://www.rfc-editor.org/rfc/rfc9116 Contact: mailto:info@sbf-consultancy.net Preferred-Languages: en, ur # Please report security vulnerabilities responsibly. # SLA Response Timelines: # - Initial acknowledgment: Within 24-72 hours. # - Critical vulnerabilities patch: Within 14 days. # - High/Medium severity patch: Within 30 days. # # Safe Harbor Policy: # SBF Consultancy will not pursue or support legal actions against security researchers # who discover and report vulnerabilities in good faith and in compliance with this policy. Policy: https://pak-llm.com/.well-known/security.txt Scope: https://pak-llm.com Scope: https://www.pak-llm.com # Out of scope: Third-party services (Firebase, Groq, HuggingFace, Vercel), # social engineering attacks, physical attacks, denial-of-service testing. Encryption: https://pak-llm.com/pgp-key.asc Acknowledgments: https://pak-llm.com/security/acknowledgments Expires: 2027-06-24T00:00:00.000Z