# Security contact for afriref. Reports reach a person, not a queue. Contact: mailto:christo@3l-groupconsulting.co.za Expires: 2027-08-24T00:00:00.000Z Preferred-Languages: en Canonical: https://afriref.dev/.well-known/security.txt # IN SCOPE, most valuable first: # * obtaining a paid answer without settling payment, or replaying a settlement # * reading another caller's data, API key, quota or alert subscription # * making us serve a figure that differs from what our cited source says # * anything reaching the host, the database, or another brand's data # NOT A VULNERABILITY: # * a paid endpoint answering 402 to an unpaid request. That is x402 working # exactly as intended. See https://afriref.dev/llms.txt # * a free pre-payment refusal (400 or 422) on a request we cannot answer. # We refuse before the paywall on purpose so you are never charged for it. # * volumetric denial of service, or raw scanner output with no proven impact # There is no paid bounty. We will credit you by name if you want that, and we # will tell you what we changed.