Coordinated security disclosure

Part of the Verify pillar. If you have found a security issue in deny.sh, please tell us. 48-hour acknowledgement, a real GPG fingerprint, safe harbour for good-faith research. Here is what to send, where to send it, and what you can expect in return.

Draft. Under review. This policy is being finalised for the 1 June launch. It already governs how we handle reports today; if you want to test it, please do.