A vulnerability disclosure policy (VDP), also referred to as a responsible disclosure policy, describes how an organization will handle reports of vulnerabilities submitted by ethical hackers. A VDP must thus be easily identifiable via a simple way, a security.txt notice.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Contact: mailto:security@nfir.nl Expires: 2026-02-01T00:00:00.000Z Encryption: https://www.nfir.nl/key.asc Preferred-Languages: NL, EN Canonical: https://www.nfir.nl/.well-known/security.txt Canonical: https://nfir.nl/.well-known/security.txt Policy: https://www.nfir.nl/responsible-disclosure/ Hiring: https://www.nfir.nl/vacatures/ -----BEGIN PGP SIGNATURE----- iHUEABYKAB0WIQSyhldssELXdWQ1tzsT9dONgWhSwgUCaFvxuwAKCRAT9dONgWhS wjQoAPwJeXIgAqa0AvwoPZY9DkAU+Qh0Yg77fldgnB1bewyffQEA3dm/vC+8cR7a cd3c0YyjZET3ux05ti/VnzpeoVbjtgY= =HABT -----END PGP SIGNATURE-----
This policy crawled by Onyphe on the 2022-07-10 is sorted as securitytxt.
FireBounty © 2015-2025