A vulnerability disclosure policy (VDP), also referred to as a responsible disclosure policy, describes how an origanisation will handle reports of vulnerabilities submitted by ethical hackers. A VDP must thus be easily identifable via a simple way, a security.txt notice.

# security.txt, as per https://tools.ietf.org/html/draft-foudil-securitytxt-10

Canonical: <a href='https://www.irfu.se/.well-known/security.txt'>https://www.irfu.se/.well-known/security.txt</a>

# Our security contact info
Contact: <a href='mailto:security@irfu.se'>security@irfu.se</a>
Contact: <a href='mailto:jan.karlsson@irfu.se'>jan.karlsson@irfu.se</a>
Contact: <a href='mailto:thomas.nilsson@irfu.se'>thomas.nilsson@irfu.se</a>
Contact: tel:+46-18-471-59-43

# PGP key
# (Thomas Nilsson, full fingerprint and URL)
Encryption: openpgp4fpr:13bb98dcf1836dfa0235b70d9c09781fc6ac9cca
Encryption: <a href='https://keyserver.ubuntu.com/pks/lookup?op=get&search=0x9c09781fc6ac9cca'>https://keyserver.ubuntu.com/pks/lookup?op=get&search=0x9c09781fc6ac9cca</a>

# Languages (English or Swedish)
Preferred-Languages: en, sv

# Expire less than a year into the future 
Expires: 30 Nov 2021 11:30:00 +0100

# All IRF (& IRFU) vacancies (not specifically security related) are adverticed on this page
# Hiring: <a href='https://www.irf.se/en/about-irf/vacancies/'>https://www.irf.se/en/about-irf/vacancies/</a>

