A vulnerability disclosure policy (VDP), also referred to as a responsible disclosure policy, describes how an organization will handle reports of vulnerabilities submitted by ethical hackers. A VDP must thus be easily identifiable via a simple way, a security.txt notice.
# Our security address(es). Two just to be safe. Contact: email@example.com Contact: firstname.lastname@example.org # Our PGP keys: Encryption: https://grothoff.org/christian/grothoff.asc Encryption: https://fdold.eu/dold.asc # Our disclosure policy: Disclosure: Full # Happy to acknowledge once there is something to acknowledge, # for now 404 as we had no incidents. Acknowledgement: https://taler.net/en/security.html
This policy crawled by Onyphe on the 2021-07-07 is sorted as securitytxt.