A vulnerability disclosure policy (VDP), also referred to as a responsible disclosure policy, describes how an organization will handle reports of vulnerabilities submitted by ethical hackers. A VDP must thus be easily identifiable via a simple way, a security.txt notice.
# To report security vulnerabilities, please find SBB's public Bug Bounty program at Intigriti. Contact: https://app.intigriti.com/programs/sbb/sbbglobal # In exceptional cases only Contact: mailto:securityissues@sbb.ch # Open positions Hiring: https://company.sbb.ch/en/jobs-careers/jobs/vacancies.html Canonical: https://www.sbb.ch/.well-known/security.txt Expires: 2025-12-31T23:59:00.000Z Preferred-Languages: en, de
This policy crawled by Onyphe on the 2025-08-06 is sorted as securitytxt.
FireBounty © 2015-2025