A vulnerability disclosure policy (VDP), also referred to as a responsible disclosure policy, describes how an origanisation will handle reports of vulnerabilities submitted by ethical hackers. A VDP must thus be easily identifable via a simple way, a security.txt notice.
# Hey there, thanks for being curious about this. # We don't yet have bug bounty program or well defined security policies, # and we likely won't need the latter as we don't collect any data. # Yet, if you decide to report something, we'll appreciate it. # If you decide to do it, please drop us a line at: Contact: firstname.lastname@example.org Preferred-Languages: en, es, ru
This policy crawled by Onyphe on the 2020-08-07 is sorted as securitytxt.