generated: '2026-08-30' method: searched source: https://www.acus.gov/vulnerability-disclosure-policy provider: Administrative Conference of the United States providerId: administrative-conference-of-the-united-states description: >- ACUS publishes a full Vulnerability Disclosure Policy (VDP) as required of federal civilian executive branch agencies by CISA Binding Operational Directive 20-01. The policy grants safe-harbor authorization for good-faith security research, names the reporting channel, states the scope, and points at the CISA Coordinated Vulnerability Disclosure process. It is published as an HTML page only — there is no RFC 9116 /.well-known/security.txt mirror on any acus.gov host (all probed 404 on 2026-08-30). program: published: true type: vulnerability-disclosure-policy url: https://www.acus.gov/vulnerability-disclosure-policy http_status: 200 policy_date: '2021-03-29' authority: CISA Binding Operational Directive 20-01 bug_bounty: false bounty_platform: null safe_harbor: true safe_harbor_text: >- "If you make a good faith effort to comply with this policy during your security research, we will consider your research to be authorized... and ACUS will not recommend or pursue legal action related to your research." contact: email: security@acus.gov submission_url: mailto:security@acus.gov?subject=VDP%20Submission security_txt: null scope: in_scope: - '*.acus.gov' out_of_scope: - Any connected service not expressly listed - Vulnerabilities in vendor-operated systems (report to the vendor) note: >- The wildcard *.acus.gov scope covers the three hosts this repo profiles — www.acus.gov, eaja.acus.gov and sourcebook.acus.gov — including the live MediaWiki Action and REST APIs on sourcebook.acus.gov. prohibited_testing: - Network denial of service (DoS/DDoS) or any test that impairs access or damages data - Physical testing, social engineering, phishing, vishing, or other non-technical testing - Using an exploit beyond confirming a vulnerability exists (no exfiltration, no persistence, no pivoting) researcher_obligations: - Report a real or potential security issue as soon as possible after discovery - Avoid privacy violations, user-experience degradation, production disruption, and data destruction - Allow reasonable time to resolve before public disclosure - Stop testing and notify immediately on encountering sensitive data or PII references: - name: CISA Coordinated Vulnerability Disclosure Process url: https://www.cisa.gov/coordinated-vulnerability-disclosure-process evidence: - url: https://www.acus.gov/vulnerability-disclosure-policy status: 200 fetched: '2026-08-30' - url: https://www.acus.gov/.well-known/security.txt status: 404 fetched: '2026-08-30' - url: https://sourcebook.acus.gov/.well-known/security.txt status: 404 fetched: '2026-08-30' recommendation: >- ACUS could earn the consent/identity and well-known signals at zero policy cost by mirroring this page as an RFC 9116 /.well-known/security.txt on www.acus.gov with Contact, Policy, Preferred-Languages and Expires fields. maintainers: - FN: Kin Lane X-twitter: apievangelist email: info@apievangelist.com