# Xplor Security Team - vulnerability disclosure # # The web form at the Contact URL below is the preferred channel and the # only one that does not require you to identify yourself. Report text # submitted through it is end-to-end encrypted in your browser and is # readable only by the security team. Attachments are malware scanned and # are therefore readable by the scanning service before they are encrypted # at rest. # # If you prefer not to trust browser-delivered JavaScript, encrypt locally # with the key at the Encryption URL and paste the ASCII-armoured block into # the report field. It is stored and handled like any other report text and # is opened manually by an analyst. We do not run an automated OpenPGP # decryption service. # # The written report is encrypted in your browser to an RSA-4096 key that # was generated inside a Key Vault HSM and cannot leave it. The key version # in use right now is 1065934afea04473a607c32f122e966b, and the form shows that same value beneath the # submit button. If the two disagree, do not submit. Contact: https://security.xplor.com/ Expires: 2027-06-30T23:59:59.000Z Encryption: https://security.xplor.com/pgp-key.txt Policy: https://security.xplor.com/policy Preferred-Languages: en Canonical: https://security.xplor.com/.well-known/security.txt