%% You should probably cite rfc9116 instead of this I-D. @techreport{foudil-securitytxt-01, number = {draft-foudil-securitytxt-01}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-foudil-securitytxt/01/}, author = {Edwin Foudil}, title = {{A Method for Web Security Policies}}, pagetotal = 11, year = 2017, month = dec, day = 3, abstract = {When security risks in web services are discovered by independent security researchers who understand the severity of the risk, they often lack the channels to properly disclose them. As a result, security issues may be left unreported. security.txt defines a standard to help organizations define the process for security researchers to securely disclose security vulnerabilities.}, }