# RFC 9116 security.txt — P5-M4.4 # Rexa.ai responsible-disclosure policy. # # No `Encryption:` field is published. It previously pointed at # /security-pgp-key.asc, which was a PLACEHOLDER containing the literal # string PENDING_REAL_PGP_KEY_GENERATION — not a usable key. A # researcher following it would have failed to import it, and an # advertised-but-broken encryption channel is worse than none: it # invites someone to attempt an encrypted report and give up. The # placeholder also published internal references (an internal doc path, # a milestone id, and where the private key would be stored). # # Restore this line only when a real public key is uploaded: # Encryption: https://rexa.ai/security-pgp-key.asc # # No `Hiring:` field either — https://rexa.ai/careers returns 404. Contact: mailto:security@rexa.ai Contact: https://rexa.ai/security Policy: https://rexa.ai/security Preferred-Languages: en Canonical: https://rexa.ai/.well-known/security.txt Expires: 2027-04-22T00:00:00.000Z