# OpenAssistant vulnerability disclosure — RFC 9116 # # NOTE FOR MAINTAINERS: the Expires field below is mandatory and an expired # security.txt is treated as invalid — worse than not publishing one, because # researchers read it as abandoned. Renew it annually and keep the date in # whatever calendar the security review runs on. Contact: mailto:security@openassistant.us Expires: 2027-02-25T00:00:00.000Z Preferred-Languages: en Canonical: https://openassistant.us/.well-known/security.txt Policy: https://openassistant.us/trust