# BookerAI security contact (RFC 9116) # TODO: a tiny route in routes/public.py needs to serve /.well-known/security.txt # from this file (Flask does not route static/.well-known/ by default). # Example: # @public_bp.get("/.well-known/security.txt") # def security_txt(): # return send_from_directory( # os.path.join(current_app.static_folder, ".well-known"), # "security.txt", # mimetype="text/plain", # ) Contact: mailto:security@booker-ai.net Expires: 2027-05-11T00:00:00.000Z Acknowledgments: https://booker-ai.net/security Policy: https://booker-ai.net/security Preferred-Languages: en Canonical: https://booker-ai.net/.well-known/security.txt