# Xplor Security Team - vulnerability disclosure # # The web form at the Contact URL below is the preferred channel and the # only one that does not require you to identify yourself. Report text # submitted through it is end-to-end encrypted in your browser and is # readable only by the security team. Attachments are malware scanned and # are therefore readable by the scanning service before they are encrypted # at rest. # # If you prefer not to trust browser-delivered JavaScript, encrypt locally # with the key at the Encryption URL and paste the ASCII-armoured block into # the report field. It is stored and handled like any other report text and # is opened manually by an analyst. We do not run an automated OpenPGP # decryption service. Contact: https://security.xplorctr.com/ Contact: mailto:security-staging@example.com Expires: 2027-06-30T23:59:59.000Z Encryption: https://security-staging.example.com/pgp-key.txt Policy: https://security-staging.example.com/policy Preferred-Languages: en Canonical: https://security.xplorctr.com/.well-known/security.txt