# Narrative Nexus — RFC 9116 security contact. # # This file is a contractual obligation, not only a courtesy: §2.4 of the C2PA # Generator Product Agreement requires a publicly accessible and prominently # displayed address for vulnerability and non-conformance reports for as long as # a generator product is listed on the C2PA Conforming Products List. # # Expires is MANDATORY in RFC 9116 and a past date makes this file invalid. # That would otherwise rot silently, so scripts/checks/check-public-static-art.mjs # fails 30 days out — in `make qg` locally, and in ci-security.yml's weekly cron, # which is the one that still fires during a quiet month. When it does: renew # this date, bump the date on /security, and re-pin this file's hash in that # same check. Contact: mailto:security@narrative.sh Expires: 2027-07-27T00:00:00.000Z Preferred-Languages: en Canonical: https://www.narrative.sh/.well-known/security.txt Policy: https://www.narrative.sh/security