# security.txt — RFC 9116 (https://www.rfc-editor.org/rfc/rfc9116.html) # # Mirrored as literal text in the page hero: SECURITY_TXT_PREVIEW in # src/pages/[lang]/bounty/index.astro. Edit one, edit the other — same # lines, same order, both sides say so. Contact: mailto:security@diagnos.health Contact: mailto:urgent@diagnos.health Policy: https://diagnos.health/en/bounty/ # Empty today, and that's accurate: the program launches with this file, so # there is nobody to acknowledge yet. The list fills in as reports land. Acknowledgments: https://diagnos.health/en/bounty/#hall-of-fame Preferred-Languages: pt-BR, en, es, it, fr # This file, at this path, is the canonical copy. If it's ever mirrored at a # bare /security.txt or on another host, that copy points back here instead # of repeating the fields. Canonical: https://diagnos.health/.well-known/security.txt # Encryption — the line below is commented out ON PURPOSE until the key is # actually published. An Encryption field pointing at a 404 is worse than no # field at all: tooling follows it, fails, and the reporter concludes the whole # channel is abandoned. # # It is uncommented automatically by: # # bun run --filter website pgp:generate # # which also writes public/.well-known/pgp-key.txt, keeps the private key and # the revocation certificate outside the repository, and records the # fingerprint in src/pages/[lang]/bounty/_config.ts. Read the header of # scripts/bounty-pgp.sh before running it. # # Encryption: https://diagnos.health/.well-known/pgp-key.txt # Required by the RFC, under one year out to force periodic review. Expires: 2027-09-16T00:00:00Z