A vulnerability disclosure policy (VDP), also referred to as a responsible disclosure policy, describes how an organization will handle reports of vulnerabilities submitted by ethical hackers. A VDP must thus be easily identifiable via a simple way, a security.txt notice.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 # Canonical URI Canonical: https://car.gov.br/.well-kown/security.txt # Our security address Contact: mailto:ctir@dataprev.gov.br Contact: mailto:dicar.seguranca@gestao.gov.br # Our OpenPGP key Encryption: https://car.gov.br/.well-known/pgp-key.txt # List of preferred languages for security reports Preferred-Languages: pt-br, en # Date and time after which this file is considered stale Expires: 2026-07-17T00:00:00z #EOF -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEs6+Sc1y6F13JfEQmwdrXNpZeWwMFAmh4jmEACgkQwdrXNpZe WwP3Og/8C/uJLltiX9Ij2jEJ9GUzKncsa6RTBBtmL9+jkn1p6cHrVpHY/Psf76lM laldbts+F+U+/MxeW1WSyUplyIrNQ8KvX0y0+kzo3avdRaT0qcWzA605U5WJIxXh NKnd9PCB8FLTLQyZpF3UtzIuL3Ea9FlbWNCGiHUP5eke4nJzhqPy/+IWGEEHNJ9B XmPRl0Nu25oh66H08RcNQGybAlLfVoiCVTOmPBaoPYqWBNlP8wJ/ujjXD2mYO32o VH1bsSeAbfPpG/YzrsvzMyY6s5m1oeEGN8n3AxCJAzlK8JzKqa2PMh9wPwyBcJaI ntqpIwh/BVBWIxTq6q9tJRsSOnqtCMqRYrjsEe+yQ7vfIDffV2FeArOuu03D6M0F qMcX791TXIgRUeqPT0w22sz1Tsk8qArsTA4P4WP0kFMPAdFS10M7DIsJ1aEwhdc2 u0oYfhw+NLpdqMqgtay7Yd3NosaoHVtaT3Qaa7DUTNSg+VCFHEbdFYpn7M64utgp QRNRG8KYHvCxL/uHxUcXdZoiI39eFfpz3ocPgopssCbihqosyH9a/ugbxIZ7Vr1x m6C5HobU8Tp9stuPKQa5JtuB9EPztBBtGQMO2gvjnAgFUlC6ABYwtoqIFnsobINy upmLfkVpOuBc98kJ7ydmkvnoGe9DZQRucjhzgfjq1sVzTQaa8/8= =m2Ij -----END PGP SIGNATURE-----
This policy crawled by Onyphe on the 2025-10-13 is sorted as securitytxt.
FireBounty © 2015-2025