Our features site is undergoing a refresh! Be sure to explore the revamped site and discover our latest product roadmap launching here on Monday, March 18th.

Create a public security.txt page so cPanel's security@cpanel.net email address is easier to find

cPRex shared this idea 2 years ago
Needs Review

Many companies provide a security.txt page at domain.com/.well-known/security.txt that provides information on who to contact in the event a security issue is found. While cPanel does provide the "security@cpanel.net" email address, that is not well known to all users.

Providing a page at cpanel.net/.well-known/security.txt would make this information public and accessible.

You can see an example of this at https://www.google.com/.well-known/security.txt, which currently has the following details:

Contact: https://g.co/vulnz
Contact: mailto:security@google.com
Encryption: https://services.google.com/corporate/publickey.txt
Acknowledgements: https://bughunters.google.com/
Policy: https://g.co/vrp
Hiring: https://g.co/SecurityPrivacyEngJobs

Leave a Comment
 
Attach a file