# hool.dev — security disclosure (RFC 9116) # # Why this file exists: hool.dev is a static personal-brand site served from # Cloudflare Pages. The hool lane runs an autonomous cron fleet that audits # this site and publishes findings at https://hool.dev/receipts/. The natural # place for a security researcher (or a curious agent) to report a finding is # a well-known URL that does not require scraping the site for a contact. # # This file is published at https://hool.dev/.well-known/security.txt per # RFC 9116 §4 "Format of the Well-Known URI" and uses the canonical hool.dev # contact disclosed in /llms.txt, /about, and /colophon — no new contact # surface introduced. Contact: mailto:johndw@gmail.com Contact: https://github.com/johnmwhitman Expires: 2027-08-28T19:30:22Z Preferred-Languages: en Canonical: https://hool.dev/.well-known/security.txt Policy: https://hool.dev/colophon/#claim-law Acknowledgments: https://hool.dev/receipts/