# ============================================================================ # SECURITY.TXT — Quorbel (Cryptographic Draw Verification Platform) # Responsible Disclosure Policy # RFC 9116 Compliant — https://securitytxt.org/ # Last Updated: 2026-06-29 # ============================================================================ # ── Contact ───────────────────────────────────────────────────────────────── # For security concerns, vulnerability reports, or cryptographic issues. # Use support@ for general security enquiries. # Use verify@ specifically for concerns about receipt integrity or signature validation. Contact: mailto:support@quorbel.com Contact: mailto:verify@quorbel.com # ── Policy ────────────────────────────────────────────────────────────────── # Quorbel's transparency page publishes the Ed25519 public key, SHA-256 # fingerprint, canonical signing specification, and full receipt schema. # This constitutes the platform's public cryptographic commitment. Policy: https://quorbel.com/transparency # ── Scope ──────────────────────────────────────────────────────────────────── # In scope for responsible disclosure: # — Ed25519 signing implementation # — SHA-256 canonical hash construction # — 256-bit CSPRNG entropy sourcing # — Entropic Domain Confinement Protocol v1 (rejection-sampling loop) # — In-browser receipt verification tool at /verify # — Signature forgery, hash collision, or entropy prediction vulnerabilities # # Out of scope: # — DoS / DDoS # — Physical infrastructure attacks # — Social engineering # — Third-party browser or device vulnerabilities # — Automated bulk scanning # ── Cryptographic Specification ────────────────────────────────────────────── # Full algorithm documentation and interactive protocol simulator: Canonical: https://quorbel.com/.well-known/security.txt # ── Expiration (required per RFC 9116) ─────────────────────────────────────── Expires: 2027-06-29T23:59:59.000Z # ── Preferred Languages ────────────────────────────────────────────────────── Preferred-Languages: en # ── Platform ───────────────────────────────────────────────────────────────── # Name : Quorbel # Etymology : Quor (quorum — many independent voices) + bel (signal unit). # "The Reputation Signal." Trust measured as a signal, not an # opinion. Quorum + Belief: trust derived from sufficient # independent evidence, not assertion. # Legal entity: One Co # Domain : https://quorbel.com # Tagline : Verification before trust. # Spec : Ed25519 · SHA-256 · CSPRNG · EDCP v1 # Transparency: https://quorbel.com/transparency # How it works: https://quorbel.com/how-it-works # ============================================================================ # END OF SECURITY.TXT # ============================================================================