# Security contact information for RootNet, operated by FlareWare. # Conforms to RFC 9116 (https://www.rfc-editor.org/rfc/rfc9116) # # This file applies to rootnet.ai and to the products and services # provided under the RootNet brand, as permitted by RFC 9116 section 3.1. # # Please report suspected vulnerabilities privately using the contact # below. Please do not disclose publicly until we have had a reasonable # chance to fix the issue. # # We will acknowledge a report within five working days. # --- REQUIRED FIELDS --- # Contact MUST be a URI, so it carries the mailto: scheme. A bare address # is the most common non-conformance in the wild. Contact: mailto:rutvik@flareware.app # RFC 3339, uppercase Z. The RFC recommends less than one year ahead. # # WHY THIS DATE AND NOT A CLOSER OR A FURTHER ONE. An expired security.txt # is worse than no security.txt: it is checkable from outside in one # request, and it tells a researcher the channel is abandoned at the exact # moment they were about to use it. So the date is chosen to be renewed on # a six month cadence with real slack, not to sit on the one year edge. # # Owner, cadence and the renewal procedure: docs/SECURITY-TXT-RENEWAL.md # `npm run prose` fails the build if this date is in the past or more than # 365 days ahead, and warns inside 60 days. It cannot lapse unnoticed. Expires: 2027-06-01T00:00:00Z # --- OPTIONAL --- Preferred-Languages: en # --- DELIBERATELY OMITTED --- # # Policy: omitted. There is no vulnerability disclosure policy page yet. # A Policy field pointing at a 404 is worse than no Policy field. # # Canonical: omitted on purpose. RFC 9116 section 2.5.2 says that if a # Canonical field is present and the URI used to fetch the file is not # listed in it, the contents SHOULD NOT be trusted. A Canonical that # misses a hostname therefore tells researchers to distrust this file. # Add it only once every hostname that serves this file is settled, and # then list all of them. # # OpenPGP signature: omitted. Signing is RECOMMENDED, not required # (RFC 9116 section 2.3). An unsigned file is fully conformant. Sign it # later, together with Canonical. # # Encryption, Acknowledgments and Hiring: add them when they exist.