A vulnerability disclosure policy (VDP), also referred to as a responsible disclosure policy, describes how an organization will handle reports of vulnerabilities submitted by ethical hackers. A VDP must thus be easily identifiable via a simple way, a security.txt notice.
# Sonic Healthcare Pty Ltd - reporting security vulnerabilities to Sonic Healthcare # Please report any security vulnerabilities to us via the contact method(s) below, only after reading our disclosure policy. # Please do not include any sensitive information in your initial message. We will provide a secure communication method in our reply to you. Contact: https://bugcrowd.com/engagements/sonic-vdp-pro Policy: https://www.sonichealthcare.com/privacy-and-security/vulnerability-disclosure-policy/ Acknowledgments: https://bugcrowd.com/engagements/sonic-vdp-pro/hall_of_fames Preferred-Languages: en Expires: 2034-05-13T13:37:00Z
This policy crawled by Onyphe on the 2025-11-03 is sorted as securitytxt.
FireBounty © 2015-2025