A vulnerability disclosure policy (VDP), also referred to as a responsible disclosure policy, describes how an organization will handle reports of vulnerabilities submitted by ethical hackers. A VDP must thus be easily identifiable via a simple way, a security.txt notice.
Canonical: https://tightenthisshitup.com/.well-known/security.txt Preferred-Languages: en Acknowledgments: https://tightenthisshitup.com/humans.txt Expires: Thu, 10 Mar 2022 15:33:33 -0400 # Stick to email for this one. Contact: mailto:firstname.lastname@example.org # All three directives point to the same key. Encryption: https://email@example.com Encryption: dns:4c1001c251c1c923bca00789638afb17e908d526bf3e9975407c65d2._openpgpkey.colincogle.name.?type=OPENPGPKEY Encryption: openpgp4fpr:3ED0663BE44765CA146AF141B9D51810CEFEEDFC
This policy crawled by Onyphe on the 2021-04-07 is sorted as securitytxt.