# norvela.app — security contact, RFC 9116 # # Norvela is a one-person studio. There is no security team and no bug bounty, # and this file says so rather than implying otherwise: a researcher who knows # what to expect is better served than one who assumes a triage rota exists. # # Every app we have shipped runs entirely on the device — no accounts, no # servers, no user data held anywhere we could lose it. On the App Store as of # 17 Sep 2026: CleanSwipe (id6807435710) and Psalm (id6809584113). The same # holds for the apps not yet released. # # The realistic surface is therefore this static site, the domain and its DNS, # and the App Store listings — not the apps themselves. # # ⚠ This file has a twin at /well-known/security.txt (no leading dot), which is # the copy Netlify actually serves; see _redirects for why. THE TWO MUST MATCH. # Scripts/security-txt-sync.sh checks it. Contact: mailto:security@norvela.app Expires: 2027-08-08T00:00:00.000Z Preferred-Languages: en Canonical: https://norvela.app/.well-known/security.txt Policy: https://norvela.app/privacy.html