# PAI'D security.txt # Conforms to RFC 9116 — A File Format to Aid in Security Vulnerability Disclosure # https://www.rfc-editor.org/rfc/rfc9116 # # Domain corrected 2026-08-23 (CAND-INTERREPO-AXIS-LAUNCH-AGENT-READINESS): this # file previously used paid.io throughout, inconsistent with robots.txt/llms.txt's # paid.trustfabric.ai. Resolved via live verification, not a guess: paid.io does # not resolve at all (DNS timeout, confirmed both server-side and from this # machine) while paid.trustfabric.ai serves the real live site — so paid.io was # never a working domain, and a paid.io security contact address would have # silently bounced. paid.trustfabric.ai is canonical everywhere in this file now. # # Honest posture statement: # - The mailto: address below is the SOLE intake channel; we do not yet # operate a HackerOne / Bugcrowd program. When we do, this file will # be updated and the canonical URL will dual-publish. # - The Encryption URL is a PLACEHOLDER pending publication of the # PAID security PGP key. The placeholder is intentional and is # tracked by scripts/check-security-txt-not-expired.ts plus a # follow-up issue in the security backlog. # - The Expires field is enforced by CI: 30 days before expiry the # CI gate WARNS; on/after expiry the CI gate ERRORS the build. Contact: mailto:security@paid.trustfabric.ai Expires: 2027-06-09T00:00:00Z Encryption: https://paid.trustfabric.ai/.well-known/pgp-key.txt Acknowledgments: https://paid.trustfabric.ai/security/acknowledgments Preferred-Languages: en Canonical: https://paid.trustfabric.ai/.well-known/security.txt Policy: https://paid.trustfabric.ai/security/responsible-disclosure