A vulnerability disclosure policy (VDP), also referred to as a responsible disclosure policy, describes how an organization will handle reports of vulnerabilities submitted by ethical hackers. A VDP must thus be easily identifiable via a simple way, a security.txt notice.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 # Canonical URI Canonical: https://www.sanity.io/.well-known/security.txt # Our security address Contact: mailto:security@sanity.io # Our OpenPGP key Encryption: https://keys.openpgp.org/search?q=security@sanity.io # Prefered language Preferred-Languages: en,no # Our security policy Policy: https://www.sanity.io/security -----BEGIN PGP SIGNATURE----- iHUEARYKAB0WIQSpYbiQOKQIwxyduCPV0yNQlc0htAUCZcOfsQAKCRDV0yNQlc0h tAlXAQDRmT3HnF8RWPT8tWPRD5LnMgANGSFmXlarpzRLJ2bd6wD/axLPHeYvHuIV iJLPzE951q956jyvTG71XoHd8seJZgU= =SbPD -----END PGP SIGNATURE-----
This policy crawled by Onyphe on the 2021-03-02 is sorted as securitytxt.
FireBounty © 2015-2024