# LLM Secrets — security contact information # https://www.rfc-editor.org/rfc/rfc9116 # # Contact fields are listed in order of preference, matching SECURITY.md: # GitHub private reporting first, email second. Contact: https://github.com/llmsecrets/llm-secrets/security/advisories/new Contact: mailto:security@llmsecrets.com # TODO: roll this forward before it lapses. An expired security.txt is treated # as invalid, not as "no policy". Expires: 2027-08-01T00:00:00.000Z # The researcher feature page. This field is what makes it findable. Acknowledgments: https://llmsecrets.com/security#hall-of-fame # SECURITY.md in the repo is canonical — timelines, scope, rewards, disclosure. Policy: https://github.com/llmsecrets/llm-secrets/blob/main/SECURITY.md Preferred-Languages: en Canonical: https://llmsecrets.com/.well-known/security.txt # No Encryption: field by design — SECURITY.md offers the PGP key on request # rather than publishing one. Add the field only if that changes.