A vulnerability disclosure policy (VDP), also referred to as a responsible disclosure policy, describes how an organization will handle reports of vulnerabilities submitted by ethical hackers. A VDP must thus be easily identifiable via a simple way, a security.txt notice.
# In the event that you have discovered a technical vulnerability in an IT system of SIX, # we encourage you to report it to us using the Coordinated Vulnerability Disclosure program. # If you are interested in participating in SIX' bug bounty programs you can apply here: https://hackerone.com/six-group Contact: https://www.six-group.com/en/contacts/services/soc.html Acknowledgements: https://github.com/sixgroup-security/bug-bounty Scope: https://hackerone.com/six-group/policy_scopes Expires: 2025-12-31T00:00:00.000Z Preferred-Languages: en, de, es Canonical: https://www.six-group.com/.well-known/security.txt Hiring: https://www.six-group.com/en/careers.html
This policy crawled by Onyphe on the 2023-10-02 is sorted as securitytxt.
FireBounty © 2015-2025