# GoRoute vulnerability disclosure contact (RFC 9116). # # Served at https://goroute.ai/.well-known/security.txt by an exact-match # location in nginx.conf.template — see the block named there. Static files on # this site are only reachable through explicit locations, so adding the file # without the location would ship it and still 404 (the mistake /llms.txt and # the IndexNow key each made). # # EXPIRES IS NOT DECORATION. RFC 9116 section 2.5.5 says a file past its Expires # date must not be trusted, so an out-of-date one is worse than none: a # researcher who finds something is told, by us, to disregard how to reach us. # Roll it forward a year each time it is renewed, and re-confirm that # security@goroute.ai still reaches a human who can act on a report. # # No Canonical field, deliberately. One image serves goroute.ai, # app.goroute.ai, every *-test cell and every white-label partner's vanity # domain, so any single canonical URI would be wrong on most of the hosts that # serve this file — and RFC 9116 section 2.5.2 says a file whose Canonical does # not match where it was fetched from should not be trusted. Omitting an # optional field beats shipping one that is false almost everywhere. Contact: mailto:security@goroute.ai Expires: 2027-08-26T00:00:00.000Z Preferred-Languages: en