# Security Contact Information for a2ml.net
# RFC 9116 Compliant: https://www.rfc-editor.org/rfc/rfc9116.html
# Consent-Aware HTTP Compatible

# === Primary Contact ===
Contact: mailto:security@a2ml.net
Contact: https://github.com/hyperpolymath/standards/tree/main/a2ml/security/advisories/new

# === Security Policy ===
Policy: https://github.com/hyperpolymath/standards/tree/main/a2ml/security/policy
Policy: https://a2ml.net/.well-known/security-policy.html

# === Encryption (PGP) ===
Encryption: https://keys.openpgp.org/search?q=jonathan.jewell@open.ac.uk
Encryption: https://github.com/hyperpolymath.gpg
Encryption: https://a2ml.net/.well-known/pgp-key.asc

# === Acknowledgments ===
Acknowledgments: https://github.com/hyperpolymath/standards/tree/main/a2ml#security-acknowledgments
Acknowledgments: https://a2ml.net/security/acknowledgments

# === Hiring (Security Team) ===
Hiring: https://github.com/hyperpolymath/standards/blob/main/a2ml/CONTRIBUTING.md

# === Preferred Languages ===
Preferred-Languages: en

# === Consent-Aware HTTP Endpoints ===
# User Consent Management (GDPR/Privacy Compliance)
# Consent-Endpoint: https://a2ml.net/api/consent
# Consent-Policy: https://a2ml.net/privacy#consent-management
# Consent-Categories: essential, functional, analytics, marketing, personalization

# === Canonical URL ===
Canonical: https://a2ml.net/.well-known/security.txt

# === CSAF (Common Security Advisory Framework) ===
# CSAF: https://a2ml.net/.well-known/csaf/provider-metadata.json

# === Expiration (1 year from creation) ===
Expires: 2027-01-31T16:43:18Z

# === Additional Information ===
# This site implements:
# - Consent-Aware HTTP (cookie-based consent verification)
# - HTTP Capability Gateway (fine-grained access control)
# - HSTS with preload (max-age=31536000)
# - TLS 1.3 minimum
# - CAA records (Let's Encrypt, DigiCert)
# - SPF, DMARC for email security
#
# Report security issues to: security@a2ml.net
# For privacy/consent issues: privacy@a2ml.net
