A vulnerability disclosure policy (VDP), also referred to as a responsible disclosure policy, describes how an origanisation will handle reports of vulnerabilities submitted by ethical hackers. A VDP must thus be easily identifable via a simple way, a security.txt notice.
# Hello! Did you find a security problem? If so we'd appreciate if you let us know. # You can e-mail us on the address below, and optionally use PGP to encrypt your message. # Thanks a bunch. We really appreciate your diligence. Contact: <a href='mailto:firstname.lastname@example.org'>email@example.com</a> Encryption: <a href='https://insomniasec.com/cdn-assets/insomniakey.asc.txt'>https://insomniasec.com/cdn-assets/insomniakey.asc.txt</a>
This policy crawled by Onyphe on the 2021-02-03 is sorted as securitytxt.