A vulnerability disclosure policy (VDP), also referred to as a responsible disclosure policy, describes how an organization will handle reports of vulnerabilities submitted by ethical hackers. A VDP must thus be easily identifiable via a simple way, a security.txt notice.
# Anglian Water - reporting security vulnerabilities to Anglian Water # Please report any security vulnerabilities to us via the contact method(s) below, only after reading our Security Disclosure Program and if you agree to its terms. # Please do not include any sensitive information (i.e. details which would allow reproduction of the vulnerability or personal data) in your initial message. We will provide a secure communication method in our reply to you. Contact: mailto:firstname.lastname@example.org # Our Security Disclosure Program. By submitting a potential security incident to us, you are accepting these terms - please read this before submitting: Program: https://www.anglianwater.co.uk/security-disclosure-program/ If you do not accept these terms, then please do not participate in the program. # Please see https://securitytxt.org/ for details of the specification of this file
This policy crawled by Onyphe on the 2021-06-06 is sorted as securitytxt.