<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.foudil-securitytxt" target="https://datatracker.ietf.org/doc/html/draft-foudil-securitytxt-03">
   <front>
      <title>A Method for Web Security Policies</title>
      <author initials="E." surname="Foudil" fullname="Edwin Foudil">
         </author>
      <author initials="Y." surname="Shafranovich" fullname="Yakov Shafranovich">
         <organization>Nightwatch Cybersecurity</organization>
      </author>
      <date month="February" day="9" year="2018" />
      <abstract>
	 <t>   When security risks in web services are discovered by independent
   security researchers who understand the severity of the risk, they
   often lack the channels to disclose them properly.  As a result,
   security issues may be left unreported. security.txt defines a
   standard to help organizations describe the process for security
   researchers to disclose security vulnerabilities securely.

	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-foudil-securitytxt-03" />
   
</reference>
