# knight-security — vulnerability disclosure policy # RFC 9116 · https://www.rfc-editor.org/rfc/rfc9116 # # Found something in my own infrastructure? Report it the same way # I would report it to you. Coordinated, documented, no drama. Contact: mailto:knightsec.research@proton.me Contact: https://t.me/knight_security Expires: 2027-07-30T00:00:00.000Z Preferred-Languages: en Canonical: https://knight-security.info/.well-known/security.txt Policy: https://knight-security.info/#roe # Encryption: PGP key fingerprint available on request. # Verify the fingerprint out of band before sending anything sensitive. # --------------------------------------------------------------- # Working the other direction — engaging me for research: # # 1. Written authorization or a published program scope, first. # 2. Coordinated disclosure, ISO/IEC 29147, 90-day standard window. # 3. Every finding ships with a working PoC, numbered reproduction # steps, a CVSS 3.1 vector and a re-test after the fix. # # Full rules of engagement: https://knight-security.info/#roe # ---------------------------------------------------------------