A vulnerability disclosure policy (VDP), also referred to as a responsible disclosure policy, describes how an organization will handle reports of vulnerabilities submitted by ethical hackers. A VDP must thus be easily identifiable via a simple way, a security.txt notice.
==================================== #LumiraDx is now a Roche Company and #vulnerability reports may be submitted #to either party for the LumiraDx estate. #If the vulnerability you report is #severity high or critical, you may be #invited to the Roche bug bounty program #where we offer bounty payments for high #or critical vulnerabilities. ==================================== Contact: mailto:security@lumiradx.com Contact: mailto:security@roche.com Policy: https://hackerone.com/lumiradx Policy: https://hackerone.com/roche Hiring: https://www.lumiradx.com/en-uk/about-us/careers Hiring: https://careers.roche.com/global/en Expires: 2025-10-19T23:00:00.000Z
This policy crawled by Onyphe on the 2025-04-02 is sorted as securitytxt.
FireBounty © 2015-2025