# RFC 9116 โ€” /.well-known/security.txt # AegisGate Security โ€” vulnerability disclosure policy # Canonical: https://aegisgatesecurity.io/.well-known/security.txt # Mirrored at: https://github.com/aegisgatesecurity/aegisgate-lens/blob/main/.well-known/security.txt # Last updated: 2026-07-02 # Contact: must appear, must be a URI Contact: mailto:security@aegisgatesecurity.io # Canonical URL: the absolute URL of this file Canonical: https://aegisgatesecurity.io/.well-known/security.txt # Expires: when this file should be re-fetched (RFC 9116 ยง2.5.4) # Format: ISO 8601 (must be within 1 year per spec) Expires: 2027-07-02T00:00:00.000Z # Acknowledgments: optional, but we like to thank reporters Acknowledgments: https://aegisgatesecurity.io/security/acknowledgments # Preferred languages for security reports Preferred-Languages: en # Policy: link to the full disclosure policy Policy: https://aegisgatesecurity.io/security/ # CVE: link to our CVE-for-AI feed (RFC 9116 extension) CVE: https://aegisgatesecurity.io/cve/ # Hiring: opt-in, link to security-related job openings # (omitted โ€” we don't have a dedicated security hiring page)