# thebrights.ai — security contact (W1 baseline) # https://www.rfc-editor.org/rfc/rfc9116 Contact: mailto:security@thebrights.ai Contact: mailto:info@thebrights.ai Expires: 2027-08-03T00:00:00.000Z Preferred-Languages: de, en Canonical: https://thebrights.ai/.well-known/security.txt Policy: https://thebrights.ai/datenschutz Acknowledgments: https://thebrights.ai/impressum # Expectation: best-effort acknowledgment within 2 business days (CET). # Scope: this marketing / W1 reference site and reported issues affecting # BrightSide Technologies GmbH web properties. Not a bug-bounty program. # CRA (EU) 2024/2847 — vulnerability / incident reporting # Early warning ≤24h / Notification ≤72h after awareness of actively exploited # vulnerability or severe incident (Art. 14, applicable from 2026-09-11). # Preferred contact for security reports: security@thebrights.ai # Internal escalation + ENISA SRP process: see ops docs (PSIRT runbook).