A vulnerability disclosure policy (VDP), also referred to as a responsible disclosure policy, describes how an organization will handle reports of vulnerabilities submitted by ethical hackers. A VDP must thus be easily identifiable via a simple way, a security.txt notice.
# Contact us by email Contact: mailto:security@psiphon.ca Preferred-Languages: en # We will only respond to credible vulnerability reports. They must contain # enough detail that we can tell they are serious and legitimate. # We do not have a formal bounty program, but any significant vulnerability # report will be considered for reward.
This policy crawled by Onyphe on the 2021-08-02 is sorted as securitytxt.
FireBounty © 2015-2024