A vulnerability disclosure policy (VDP), also referred to as a responsible disclosure policy, describes how an organization will handle reports of vulnerabilities submitted by ethical hackers. A VDP must thus be easily identifiable via a simple way, a security.txt notice.
# In the event that you have discovered a technical vulnerability in an IT system of SIX, # we encourage you to report it to us using the Coordinated Vulnerability Disclosure program. # If you are interested in participating in SIX' bug bounty programs you can apply here: https://hackerone.com/six-group Contact: https://www.six-group.com/en/contacts/services/soc.html Expires: 2024-12-31T00:00:00.000Z Preferred-Languages: en, de, es Canonical: https://www.six-group.com/.well-known/security.txt Hiring: https://jobs.six-group.com/search Hiring: https://www.six-group.com/en/careers.html Hiring: https://www.six-group.com/de/careers.html
This policy crawled by Onyphe on the 2022-07-10 is sorted as securitytxt.
FireBounty © 2015-2025