Operational guidelines, vulnerability disclosure protocol, cryptographic verification keys, and engineering standards for newjosh.com.
As an independent systems architect, I welcome high-quality vulnerability research and coordinated disclosure. Research conducted within the scope of this policy is deemed authorized, and I will not pursue civil or criminal actions against good-faith researchers.
For secure or sensitive communication, please encrypt your transmission using my sovereign RSA-4096 OpenPGP public key:
newjosh.com primary site and static assetsDeclared at /.well-known/security.txt with rolling annual expiry and OpenPGP key linkage.
Full isolation enabled via Cross-Origin-Embedder-Policy: credentialless and Cross-Origin-Opener-Policy: same-origin.
Strict Content-Security-Policy, base-uri 'self', object-src 'none', form-action 'self'.
CycloneDX SBOM tracking and pinned package integrity hashes across all dependencies.