specification: API Commons Vulnerability Disclosure specificationVersion: '0.1' provider: Administration for Community Living (ACL) providerId: administration-for-community-living-acl- generated: '2026-08-30' method: searched source: >- https://www.hhs.gov/vulnerability-disclosure-policy/index.html — the URL ACL ships in the footer of its own web applications (found verbatim in the eldercare.acl.gov Next.js bundle alongside acl.gov, hhs.gov and usa.gov). description: >- ACL does not run its own vulnerability disclosure programme. As an operating division of the US Department of Health and Human Services it is covered by the department-wide HHS Vulnerability Disclosure Policy, and ACL links that policy from the footer of its own properties. That link is the disclosure channel a researcher would actually use for an acl.gov finding. program: type: department-wide-vdp owner: US Department of Health and Human Services url: https://www.hhs.gov/vulnerability-disclosure-policy/index.html scope_note: >- HHS publishes this policy under CISA Binding Operational Directive 20-01, which requires it to cover the department's internet-accessible systems — acl.gov and its subdomains among them. ACL is an HHS operating division, which is why an ACL-owned policy does not exist separately. bug_bounty: false bug_bounty_platform: null security_txt: present: false probed: - url: https://acl.gov/.well-known/security.txt status: 404 - url: https://sic.acl.gov/.well-known/security.txt status: 404 - url: https://ehc.acl.gov/.well-known/security.txt status: 404 - url: https://agid.acl.gov/.well-known/security.txt status: 200 result: miss note: React SPA catch-all returned the application HTML shell, not a security.txt. - url: https://eldercare.acl.gov/.well-known/security.txt status: 200 result: miss note: Next.js catch-all returned the application HTML shell, not a security.txt. evidence: - url: https://www.hhs.gov/vulnerability-disclosure-policy/index.html status: 403 note: >- hhs.gov returns 403 Access Denied to non-browser clients (Akamai edge policy). Attempted with a browser User-Agent and full browser Accept headers, and via a second independent fetcher; both were refused. The link is recorded as present-but-unread rather than verified live, and rather than dead. - url: https://acl.gov/ status: 200 note: ACL properties are the source of the link. gaps: - No security.txt on any ACL host. - No ACL-specific disclosure contact or PGP key. - No bug bounty. - No coordinated-disclosure or safe-harbour statement on any acl.gov page itself. maintainers: - FN: Kin Lane X-twitter: apievangelist email: info@apievangelist.com