# RFC 9116. Where to send a security report about dot.bm or any dotbm product. # # Not on Cloudflare's agent-readiness list. It is here because dotbm publishes a # guide on hardening Authorize.Net merchant accounts, and a studio that tells # other people to close their holes should have a published address for its own. # # Expires is mandatory and is the field that rots. Nothing warns when it passes; # the file just becomes formally invalid while still looking fine. Renew this on # or before 2027-10-09 by moving the date a year out. That is the whole # maintenance task, and it is deliberately a hand edit rather than a build-time # stamp or a cron, because neither is worth standing up for one line a year. Contact: mailto:security@dot.bm Policy: https://dot.bm/trust/ Expires: 2027-10-09T00:00:00.000Z Preferred-Languages: en Canonical: https://dot.bm/.well-known/security.txt