# Principle Breach (Adversary Holdings Private Limited) # Machine-readable security contact information, per RFC 9116. # Human-readable vulnerability disclosure policy: https://principlebreach.com/security # # --------------------------------------------------------------------------- # MAINTENANCE -- READ BEFORE THE DATE BELOW # # `Expires` is a hard deadline, not a hint. RFC 9116 Section 2.5.5 says the data in # this file MUST be considered stale once that timestamp passes, and consumers # are expected to ignore a lapsed file. An offensive security company serving # an expired security.txt is worse than serving none. # # Re-issue before 2027-08-01: bump `Expires` to no more than one year out, # re-check that every URI below still resolves, and confirm the fingerprint # still matches the key at /pgp-key.txt. The file is a static asset in # public/.well-known/security.txt -- edit it there and redeploy. # # --------------------------------------------------------------------------- # SIGNING # # This file is deliberately unsigned. RFC 9116 Section 2.3 says it SHOULD carry an # OpenPGP cleartext signature; doing that properly means running # `gpg --clearsign security.txt` with the key whose fingerprint is below and # committing the signed output in place of this file, as part of the re-issue # above. Do not hand-write a signature block, and do not add a `Signature:` # field -- it is not an RFC 9116 field and a fabricated signature would be a # straightforward integrity failure on the one file whose job is integrity. # --------------------------------------------------------------------------- Contact: mailto:hello@principlebreach.com Contact: tel:+919202501337 Contact: https://principlebreach.com/security Expires: 2027-08-01T00:00:00.000Z Encryption: https://principlebreach.com/pgp-key.txt Encryption: openpgp4fpr:c3dc3424cbe30b9459affbb89b068774ae243bb4 Preferred-Languages: en Canonical: https://principlebreach.com/.well-known/security.txt Policy: https://principlebreach.com/security # No `Acknowledgments` and no `Hiring` field: there is no acknowledgements page # and no open-roles page to point at. An RFC 9116 field pointing at a 404 is a # broken promise, so neither is published until the page exists.