Skip to main content
Regulaxy
/.well-known/security.txt
# ─────────────────────────────────────────────────────────────────────────────
# ⛔ DRAFT — every [PLACEHOLDER] below must be replaced before this domain goes
#    live. RFC 9116 makes `Contact` and `Expires` MANDATORY, and `Expires` must
#    appear exactly once and be less than a year in the future. A security.txt
#    that does not parse, or one that has expired, is worse on a security
#    vendor's domain than none at all — researchers do check.
#
#    ⚠ `Expires` is a MAINTENANCE COMMITMENT. Put a calendar reminder at eleven
#      months. Renewing it is a two-minute job that nobody remembers to do.
#
#    Source: WEBSITE-STRATEGY.md Appendix A.4. Kept in sync with the human-
#    readable policy at /trust/vulnerability-disclosure, which renders this
#    exact file so the two cannot drift.
# ─────────────────────────────────────────────────────────────────────────────

# Security contact information for [PLACEHOLDER: company name]
# See https://www.rfc-editor.org/rfc/rfc9116

Contact: mailto:security@[PLACEHOLDER: domain]
Contact: https://[PLACEHOLDER: domain]/trust/vulnerability-disclosure
Expires: [PLACEHOLDER: e.g. 2027-06-30T23:59:00.000Z]
Preferred-Languages: he, en
Canonical: https://[PLACEHOLDER: domain]/.well-known/security.txt
Policy: https://[PLACEHOLDER: domain]/trust/vulnerability-disclosure
Acknowledgments: https://[PLACEHOLDER: domain]/trust/hall-of-fame
Encryption: https://[PLACEHOLDER: domain]/.well-known/pgp-key.txt
Hiring: https://[PLACEHOLDER: domain]/company/careers