A vulnerability disclosure policy (VDP), also referred to as a responsible disclosure policy, describes how an organization will handle reports of vulnerabilities submitted by ethical hackers. A VDP must thus be easily identifiable via a simple way, a security.txt notice.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 # Our primary reporting channel: Contact: mailto:security@thinkst.com Encryption: https://thinkst.com/pgp/security.txt Preferred-Languages: en # Alternative channel for canarytokens.org vulnerabilities: Contact: https://github.com/thinkst/canarytokens/security/advisories/new Policy: https://github.com/thinkst/canarytokens/security/policy Acknowledgements: https://github.com/thinkst/canarytokens/security/advisories Canonical: https://canarytokens.org/.well-known/security.txt Expires: 2026-12-31T21:59:00.000Z Hiring: https://canary.tools/hiring -----BEGIN PGP SIGNATURE----- Comment: GPGTools - https://gpgtools.org iHUEARYKAB0WIQQ0wBgfavdBT+P6QEFVZt5K9AEpCAUCaPdywgAKCRBVZt5K9AEp CAmaAQDjdpTlsPKDX/i4KC3fBxFtlqHOhjeM2xyiH+wqylnP8QEAy7wBZ+MyJGSC ZojmHhaTWN7pfRoeTXLZnqoeqfRx+AY= =u1Af -----END PGP SIGNATURE-----
This policy crawled by Onyphe on the 2026-01-02 is sorted as securitytxt.
FireBounty © 2015-2026