# VPSDEN security contact # https://www.rfc-editor.org/rfc/rfc9116 Contact: mailto:security@vpsden.com Contact: https://vpsden.com/contact Preferred-Languages: en, fr, de, ru Canonical: https://vpsden.com/.well-known/security.txt Expires: 2027-07-01T00:00:00.000Z # Encryption: withheld deliberately, not forgotten. # https://vpsden.com/pgp.txt currently serves prose explaining that no OpenPGP key # has been generated yet. Naming it here would point a client at a file with no key # in it. The field, the fingerprint on /contact and the download button are all # driven by SITE.pgpKeyServed in src/lib/site.ts and appear together the moment a # real key is exported over /pgp.txt. Confidential submission, advisory signatures # and the canary signature all come off that key; none of them exists today. # The Policy: and Acknowledgments: fields are absent rather than pointing at URLs # that 404. Restore each one only when the artefact behind it exists: # Policy: a disclosure policy page at /legal/security-policy # Acknowledgments: a credits page at /security/hall-of-fame # # We pay bounties and we credit researchers publicly unless asked not to. Safe # harbour applies to good-faith research that does not access other customers’ # data, degrade service, or exfiltrate anything beyond a proof of concept. # # Of particular interest: # - Anything that would let us read a customer’s LUKS-encrypted volume # - Any way to bypass the dead-man switch or duress PIN # - Any discrepancy between the GHOST image we serve and what actually boots # - Any log or sample we claim not to collect but in fact do