A vulnerability disclosure policy (VDP), also referred to as a responsible disclosure policy, describes how an organization will handle reports of vulnerabilities submitted by ethical hackers. A VDP must thus be easily identifiable via a simple way, a security.txt notice.
Contact: security-alert@sophos.com Contact: https://www.sophos.com/security Contact: https://bugcrowd.com/sophos Encryption: https://www.sophos.com/en-us/legal/sophos-responsible-disclosure-policy Policy: https://www.sophos.com/security Acknowledgement: https://www.sophos.com/en-us/legal/sophos-responsible-disclosure-policy/thanks.aspx Signature: https://www.hitmanpro.com/.well-known/security.txt.sig
This policy crawled by Onyphe on the 2021-05-01 is sorted as securitytxt.
FireBounty © 2015-2024