A vulnerability disclosure policy (VDP), also referred to as a responsible disclosure policy, describes how an organization will handle reports of vulnerabilities submitted by ethical hackers. A VDP must thus be easily identifiable via a simple way, a security.txt notice.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Contact: mailto:servicedesk@lochem.nl Expires: 2025-10-11T11:58:00.000Z Policy: https://www.lochem.nl//coordinatedvulnerabilitydisclosure Preferred-Languages: nl, en Canonical: https://www.lochem.nl/.well-known/security.txt Encryption: https://keyserver.ubuntu.com/pks/lookup?search=770453326969D905714BEDE8E9612CE5E9F36503&fingerprint=on&op=index -----BEGIN PGP SIGNATURE----- iHUEARYKAB0WIQR3BFMyaWnZBXFL7ejpYSzl6fNlAwUCZw92IAAKCRDpYSzl6fNl AyiRAQCzrXdGiOGy9/Lc1iBrJjdmiRAHedn6RQm+IeYTAN6RcQD9E93NbaTCMqyn XI0ZONodAmCX7qhrSBc7v94YS3ZQCAs= =pCoo -----END PGP SIGNATURE-----
This policy crawled by Onyphe on the 2025-11-03 is sorted as securitytxt.
FireBounty © 2015-2025