# Security contact for the 11/11 AI control plane. # Format: RFC 9116. Contact: mailto:quantum@11aiblockchain.com Expires: 2027-08-18T23:59:59.000Z Preferred-Languages: en Canonical: https://control.11aiblockchain.com/.well-known/security.txt # What we want to hear about # # Anything that would let someone other than us cause a record to be signed or # published, alter or delete a published record, or make this control plane # state something that is not true. Reports about the public verification path # are especially welcome: if a documented command does not reproduce, if a # published algorithm name does not match what the endpoint actually emits, or # if a signature we assert is valid does not verify on your machine, tell us. # We would rather learn it from you than have an evaluator find it. # # Verify before you report, if you can. No API key is needed: # # curl -s https://control.11aiblockchain.com/v1/public/evidence # curl -s https://control.11aiblockchain.com/.well-known/jwks.json # # Reference verifier: https://github.com/11-11AI/verify-11ai-proof # # What to expect # # Acknowledgement within 3 business days. We will tell you what we found, what # we changed, and when. If we disagree that something is a vulnerability we # will say so and say why, rather than going quiet. # # Good-faith testing against the public read-only endpoints listed above is # welcome. Please do not run denial-of-service tests, do not attempt to access # other parties' data, and do not test any host not listed under Canonical. # # Please do not include credentials, keys, or tokens in a report. If you found # one, tell us where it is and we will retrieve it ourselves. # # 11 AI Blockchain Developments LLC