# Sparko — security contact and disclosure policy (RFC 9116) # # Published as a text file rather than relying on the mailto link on # /trust: Cloudflare's email-address obfuscation rewrites addresses in # HTML into a JS-decoded placeholder, so a non-JS client — including # most crawlers and scripted tooling — cannot read it there. Contact: mailto:security@sparko.app Expires: 2027-08-15T00:00:00.000Z Preferred-Languages: en Canonical: https://sparko.app/.well-known/security.txt Policy: https://sparko.app/trust # We won't pursue legal action against good-faith research that respects # customer data and avoids privacy violations, service disruption, or # data destruction. Tell us what you found and how to reproduce it; we'll # acknowledge your report and keep you updated as we work on it.