<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet type="text/xsl" href="security-txt-fields.xsl"?>
<?xml-model href="security-txt-fields.rng" schematypens="http://relaxng.org/ns/structure/1.0" ?>
<registry xmlns="http://www.iana.org/assignments" id="security-txt-fields">
  <title>security.txt Fields</title>
  <created>2021-07-13</created>
  <updated>2026-03-07</updated>

  <registry id="security-txt-fields">
    <title>security.txt Fields</title>
    <xref type="rfc" data="rfc9116"/>
    <registration_rule>Expert Review</registration_rule>
    <expert>Yakov Shafranovich, Edwin Foudil</expert>
    <record date="2021-07-13">
      <value>Acknowledgments</value>
      <description>link to page where security researchers are recognized</description>
      <appearance>yes</appearance>
      <status>current</status>
      <controller>IETF</controller>
      <xref type="rfc" data="rfc9116"/>
    </record>
    <record date="2021-07-13">
      <value>Canonical</value>
      <description>canonical URI for this file</description>
      <appearance>yes</appearance>
      <status>current</status>
      <controller>IETF</controller>
      <xref type="rfc" data="rfc9116"/>
    </record>
    <record date="2021-07-13">
      <value>Contact</value>
      <description>contact information to use for reporting vulnerabilities</description>
      <appearance>yes</appearance>
      <status>current</status>
      <controller>IETF</controller>
      <xref type="rfc" data="rfc9116"/>
    </record>
    <record date="2023-02-15">
      <value>CSAF</value>
      <description>Link to a provider-metadata.json resource of the Common Security Advisory Framework (CSAF)</description>
      <appearance>yes</appearance>
      <status>current</status>
      <controller><xref type="person" data="OASIS_Open"/></controller>
      <xref type="uri" data="https://docs.oasis-open.org/csaf/csaf/v2.0/os/csaf-v2.0-os.html">Common Security Advisory Framework Version 2.0, OASIS Standard</xref>
    </record>
    <record date="2021-07-13">
      <value>Expires</value>
      <description>date and time after which this file is considered stale</description>
      <appearance>no</appearance>
      <status>current</status>
      <controller>IETF</controller>
      <xref type="rfc" data="rfc9116"/>
    </record>
    <record date="2021-07-13">
      <value>Encryption</value>
      <description>link to a key to be used for encrypted communication</description>
      <appearance>yes</appearance>
      <status>current</status>
      <controller>IETF</controller>
      <xref type="rfc" data="rfc9116"/>
    </record>
    <record date="2021-07-13">
      <value>Hiring</value>
      <description>link to the vendor's security-related job positions</description>
      <appearance>yes</appearance>
      <status>current</status>
      <controller>IETF</controller>
      <xref type="rfc" data="rfc9116"/>
    </record>
    <record date="2021-07-13">
      <value>Policy</value>
      <description>link to security policy page</description>
      <appearance>yes</appearance>
      <status>current</status>
      <controller>IETF</controller>
      <xref type="rfc" data="rfc9116"/>
    </record>
    <record date="2021-07-13">
      <value>Preferred-Languages</value>
      <description>list of preferred languages for security reports</description>
      <appearance>no</appearance>
      <status>current</status>
      <controller>IETF</controller>
      <xref type="rfc" data="rfc9116"/>
    </record>
    <record date="2026-03-07">
      <value>Bug-Bounty</value>
      <description>A project or company that may financially reward reporters via 
a bug bounty program as per section 3.5.5 of [CERT.CVD] can indicate this by adding 
the line "Bug-Bounty: True". Adding the line "Bug-Bounty: False" indicates that no 
financial reward via a bug bounty program can be offered.</description>
      <appearance>no</appearance>
      <status>current</status>
      <controller>IETF</controller>
      <xref type="uri" data="https://www.sei.cmu.edu/documents/1945/2017_003_001_503340.pdf">Software Engineering Institute, 
"The CERT Guide to Coordinated Vulnerability Disclosure", Carnegie Mellon University, CMU/SEI-2017-SR-022, August 2017</xref>
    </record>
  </registry>

  <people>
    <person id="OASIS_Open">
      <name>OASIS Open</name>
      <uri>mailto:project-admin&amp;oasis-open.org</uri>
      <uri>https://www.oasis-open.org</uri>
      <updated>2023-02-15</updated>
    </person>
  </people>
</registry>
