A vulnerability disclosure policy (VDP), also referred to as a responsible disclosure policy, describes how an organization will handle reports of vulnerabilities submitted by ethical hackers. A VDP must thus be easily identifiable via a simple way, a security.txt notice.
# eCosCentric Limited - reporting security vulnerabilities to eCosCentric # Please report any security vulnerabilities to us via the contact method # below. Contact: mailto:security@ecoscentric.com # Date for expiration of this file/for internal review: Expires: 2023-02-01T00:00:00.000Z # eCosCentric operates a Coordinated (aka Responsible) Disclosure policy. # We do not offer a Bug Bounty. # Policy: https://www.ecoscentric.com/security.shtml # # If you believe you've found an issue in a product incorporating our # real-time embedded software then please contact the hardware manufacturer # directly - as a result of having published a lot of our work as open source, # or having supplied software under a self-service evaluation/Non-Commercial # license, we may not have current/direct links with a product's end-manufacturer. # # For issues relating to development with eCosPro, developers should first # search for applicable updates at https://bugzilla.ecoscentric.com using # their company credentials to login. # # We also welcome reports (to the email address above) of any issues affecting # the proper operation of eCosCentric's website, support systems and # community infrastructure that we host - often such issues are transient # supplier problems, but we'd much rather be aware ;-) # # Please see https://securitytxt.org/ for details of the specification of this file
This policy crawled by Onyphe on the 2021-05-02 is sorted as securitytxt.
FireBounty © 2015-2024