# Static fallback (RFC 9116). In production the frontend is served via server.mjs, # which proxies /.well-known/security.txt to the backend so the contact + expiry # come from Settings and stay current. Update the values below if you deploy the # static dist/ without server.mjs. Expires MUST be a future date. Contact: mailto:security@adsgilla.in Expires: 2027-01-01T00:00:00Z Policy: /page/vulnerability-disclosure Preferred-Languages: en, hi