# security.txt (RFC 9116) # VisionForge / Metropolis VLM — vulnerability disclosure contact. # # Groundwork for GitHub issue #26 (SOC2 Type I/II gap analysis, Epic #19). # See docs/SECURITY.md and docs/trust/soc2-gap-analysis.md for the full # current-state security posture. This file does NOT imply any certification. # # TODO (needs a human decision, not automatable from here): replace the # contact below with an official monitored security inbox/alias before # relying on this for real disclosures. Contact: mailto:security@tribucorp.example Preferred-Languages: es, en Canonical: https://visionforge.example/.well-known/security.txt Policy: https://visionforge.example/trust Expires: 2027-08-05T00:00:00.000Z