# Responsible disclosure policy for 3FA (RFC 9116). # Keep Expires under a year and refresh it on each release. # TODO(security): publish a PGP key and add an `Encryption:` field so reporters # can send vulnerabilities encrypted. Contact: mailto:security@threefa.app Expires: 2026-12-11T00:00:00.000Z Preferred-Languages: en Canonical: https://threefa.app/.well-known/security.txt Policy: https://threefa.app/security