A vulnerability disclosure policy (VDP), also referred to as a responsible disclosure policy, describes how an organization will handle reports of vulnerabilities submitted by ethical hackers. A VDP must thus be easily identifiable via a simple way, a security.txt notice.
# Our security address(es). Two just to be safe. Contact: grothoff@gnunet.org Contact: schanzen@gnunet.org # Our PGP keys: Encryption: https://grothoff.org/christian/grothoff.asc Encryption: https://schanzen.eu/schanzen.asc # Our disclosure policy: Disclosure: Full # Happy to acknowledge once there is something to acknowledge, # for now 404 as we had no incidents. Acknowledgement: https://gnunet.org/en/security.html
This policy crawled by Onyphe on the 2021-11-04 is sorted as securitytxt.
FireBounty © 2015-2024