This file is a PLACEHOLDER. It is not a valid PGP key and must not be used to encrypt anything sent to cve@dewaguard.com. Before going live, replace this file with a real exported public key: gpg --armor --export cve@dewaguard.com > pgp.txt If no real key exists yet, remove the references to this file from index.html, policy/index.html, and .well-known/security.txt instead of shipping a dead link — a broken PGP pointer is worse than no PGP pointer.