I have heard security researchers suggest that if you run a public website, you should put up a "security contact" page that includes a contact email address and your PGP public key so that people can contact you if they discover any security vulnerabilities.
One example of this is http://37signals.com/security-response.
1) What is the intended purpose of including your PGP key on this page?
2) How can you be sure that someone didn't compromise the server and put up their own PGP key?