Skip to content
Sovereign Security Posture

Security Architecture & Responsible Disclosure

Operational guidelines, vulnerability disclosure protocol, cryptographic verification keys, and engineering standards for newjosh.com.

Last Audited: September 6, 2026 · Scope: newjosh.com

Responsible Vulnerability Disclosure & Safe Harbor

As an independent systems architect, I welcome high-quality vulnerability research and coordinated disclosure. Research conducted within the scope of this policy is deemed authorized, and I will not pursue civil or criminal actions against good-faith researchers.

Primary Inbox
Direct triage by Joshua M. Abrams
SLA Commitment
≤ 48-Hour Response
Direct technical triage & confirmation
Safe Harbor Terms: Good-faith research requires respecting user privacy, avoiding destruction of data, and refraining from denial of service. Please provide 60 days before public disclosure.

OpenPGP Cryptographic Key

For secure or sensitive communication, please encrypt your transmission using my sovereign RSA-4096 OpenPGP public key:

// Personal Sovereign OpenPGP Key
Fingerprint: 2513 6ACA 4FC4 2E92 EBCE 6D59 55FB 2F64 3CF7 31FB
User ID: Joshua M. Abrams <security@newjosh.com>

Research Scope & Boundaries

In-Scope
  • newjosh.com primary site and static assets
  • Client-side interactive sandboxes and simulations
  • Security headers, CSP enforcement, and COEP isolation
  • DNS and cryptographic certificate configurations
Out-of-Scope
  • Denial of Service (DoS / DDoS) testing
  • Automated volume vulnerability spam scanners
  • Social engineering or spear-phishing
  • Attacks on third-party newsletter delivery infrastructure

Standards Alignment & Supply Chain

RFC 9116 Manifest

Declared at /.well-known/security.txt with rolling annual expiry and OpenPGP key linkage.

Cross-Origin Isolation

Full isolation enabled via Cross-Origin-Embedder-Policy: credentialless and Cross-Origin-Opener-Policy: same-origin.

OWASP ASVS 5.0.0

Strict Content-Security-Policy, base-uri 'self', object-src 'none', form-action 'self'.

Supply Chain Transparency

CycloneDX SBOM tracking and pinned package integrity hashes across all dependencies.