generated: '2026-08-26' method: searched source: https://github.com/phosphorusinc/public note: >- Phosphorus publishes a dedicated security contact and a PGP public key for it, in its own public GitHub organization -- the only vulnerability-reporting channel it publishes anywhere. It is thin and old, and that is recorded here rather than dressed up: the repository was last pushed on 2017-06-12, there is no disclosure policy, no safe-harbour statement, no scope definition, no response-time commitment, and no bug bounty. RFC 9116 is not served: /.well-known/security.txt returns 404 on phosphorus.io and on every other Phosphorus host probed. The key file itself is deliberately NOT copied into this repository -- it is linked, so the provider's own copy stays the source of truth. published: true program_type: security-contact contact: email: security@phosphorus.io pgp_key_url: https://github.com/phosphorusinc/public/blob/master/security%40phosphorus.io.asc pgp_key_raw: https://raw.githubusercontent.com/phosphorusinc/public/master/security@phosphorus.io.asc pgp_key_source: Keybase OpenPGP v2.0.71 -- https://keybase.io/phosphorusinc key_published: '2017-06-12' policy_url: null safe_harbour: false scope_defined: false response_commitment: null bug_bounty: program: none platforms_checked: - hackerone - bugcrowd - intigriti found: false security_txt: served: false evidence: - url: https://phosphorus.io/.well-known/security.txt status: 404 - url: https://api.phosphorus.io/.well-known/security.txt status: 503 - url: https://docs.phosphorus.io/.well-known/security.txt status: 403 - url: https://support.phosphorus.io/.well-known/security.txt status: 404 evidence: - url: https://github.com/phosphorusinc/public status: 200 finding: repository contains README.md and security@phosphorus.io.asc - url: https://raw.githubusercontent.com/phosphorusinc/public/master/security@phosphorus.io.asc status: 200 finding: 4,704-byte PGP PUBLIC KEY BLOCK, Keybase-generated, for security@phosphorus.io