A vulnerability disclosure policy (VDP), also referred to as a responsible disclosure policy, describes how an organization will handle reports of vulnerabilities submitted by ethical hackers. A VDP must thus be easily identifiable via a simple way, a security.txt notice.
# _ _ _ _ ___ # _| | ___ _| |_ ___ ___ _| |_ <_>| | '_ _ # / . |/ ._> | | / ._>/ | ' | | | || |-| | | # \___|\___. |_| \___.\_|_. |_| |_||_| `_. | # "Pool on the roof must have a leak." <___' # Reporting Security-page: https://detectify.com/responsible_disclosure Contact: disclosure@detectify.com # Scope In-scope: *.detectify.com Out-of-scope: blog.detectify.com Out-of-scope: labs.detectify.com Out-of-scope: support.detectify.com Out-of-scope: career.detectify.com
This policy crawled by Onyphe on the 2020-04-29 is sorted as securitytxt.
FireBounty © 2015-2024