A vulnerability disclosure policy (VDP), also referred to as a responsible disclosure policy, describes how an organization will handle reports of vulnerabilities submitted by ethical hackers. A VDP must thus be easily identifiable via a simple way, a security.txt notice.
# Our Security Adress Contact: mailto:voc@carrefour.com # Our OpenPGP key Encryption: https://www.carrefour.com/.well-known/security-carrefour-pubkey.txt Canonical: https://www.carrefour.com/.well-known/security.txt # Our Security Policy Policy: https://carrefour.com/disclosure # Expiration Expires: 2026-01-16T18:15:00.000Z # Languages Preferred-Languages: en,fr # Special thanks Acknowledgments: https://www.carrefour.com/.well-known/hall-of-fame.txt
This policy crawled by Onyphe on the 2023-12-01 is sorted as securitytxt.
FireBounty © 2015-2025