# Speech by Creativefuel - coordinated vulnerability disclosure (RFC 9116) # # If you have found a security issue in Speech - the apps, speech.rupees.com, # or the API - please tell us before you tell anyone else. We will reply, # we will keep you updated while we fix it, and we will not pursue legal # action against anybody who follows this. Contact: mailto:security@creativefuel.io Expires: 2027-09-04T00:00:00.000Z Preferred-Languages: en, hi Canonical: https://speech.rupees.com/.well-known/security.txt Policy: https://speech.rupees.com/trust.html # What we would especially like to hear about: # - anything that reaches one account's dictations, audio or account data # from another account # - anything that gets past the admin console's owner gate or its second # factor # - anything that lets a SCIM token for one organization touch another's # # Please do not run load tests, denial-of-service tests, or automated # scanners against production, and please do not access, modify or keep any # real person's dictation data. If a proof of concept needs an account, ask # us and we will make you one.