A vulnerability disclosure policy (VDP), also referred to as a responsible disclosure policy, describes how an origanisation will handle reports of vulnerabilities submitted by ethical hackers. A VDP must thus be easily identifable via a simple way, a security.txt notice.
# Our security address(es). Two just to be safe. Contact: <a href='mailto:firstname.lastname@example.org'>email@example.com</a> Contact: <a href='mailto:firstname.lastname@example.org'>email@example.com</a> # Our PGP keys: Encryption: <a href='https://grothoff.org/christian/grothoff.asc'>https://grothoff.org/christian/grothoff.asc</a> Encryption: <a href='https://schanzen.eu/schanzen.asc'>https://schanzen.eu/schanzen.asc</a> # Our disclosure policy: Disclosure: Full # Happy to acknowledge once there is something to acknowledge, # for now 404 as we had no incidents. Acknowledgement: <a href='https://gnunet.org/en/security.html'>https://gnunet.org/en/security.html</a>
This policy crawled by Onyphe on the 2020-11-06 is sorted as securitytxt.