Compound AI OpsCOMPOUND LINKEDIN8 September 2026
We now reject expired security.txt before sharing contacts
A security researcher can reach an expired contact address, and that address can still receive a report.
The security.txt standard requires an expiry date, while a hand-written file keeps its old date until we edit it.
We set that date to the first day of the month one year ahead. Our separate expiry check reads the date before we share the address.
That check rejects an expired file before we point a researcher to its contact address.
<caption>A contact file kept an old expiry date, so our separate check blocks it before we share the address.</caption>
#software