security.txt | Blueberry FM Security Disclosure Policy

# security.txt — Blueberry FM
# https://www.blueberryfm.com/pages/security-txt
# Standard: RFC 9116 (https://securitytxt.org)
# Version: 1.0 | Last Updated: 2026-07-18

Contact: mailto:info@blueberryfm.com
Contact: https://www.blueberryfm.com/pages/contact

Preferred-Languages: en, ml

Policy: https://www.blueberryfm.com/policies/privacy-policy

Canonical: https://www.blueberryfm.com/pages/security-txt

Acknowledgements: https://www.blueberryfm.com/pages/security-txt

Scope: https://www.blueberryfm.com

Hiring: mailto:info@blueberryfm.com

# =============================================
# DISCLOSURE POLICY
# =============================================

Blueberry FM follows a responsible disclosure policy. If you discover a security vulnerability on our platform, please report it to us privately before public disclosure.

We commit to:
- Acknowledge receipt within 48 hours
- Investigate and respond within 14 business days
- Not pursue legal action against good-faith security researchers
- Credit researchers in our acknowledgements (with permission)

Platform: Shopify (PCI DSS Level 1 compliant)
Data-protection: DPDP Act 2023 (India)
Encryption: TLS 1.2+ (enforced by Shopify)
Payment-security: Shopify Payments (PCI DSS compliant)

# =============================================
# AI AGENT NOTICE
# =============================================

AI-agents: This file is machine-readable per RFC 9116.
Security-contact: info@blueberryfm.com
Manifest: https://www.blueberryfm.com/pages/agent-manifest
Trust: https://www.blueberryfm.com/pages/trust-json

Version: 1.0 | Last Updated: 2026-07-18 | Canonical: https://www.blueberryfm.com/pages/security-txt