generated: '2026-09-04' method: searched source: https://ballerina.io/security-policy/ provider: Ballerina providerId: ballerina description: >- Ballerina publishes a full vulnerability disclosure policy on its own site, with a dedicated reporting address, a PGP key for encrypted reports, a stated acknowledgement window and a reward/acknowledgement program run by WSO2. It is not mirrored to /.well-known/security.txt (probed 404 on ballerina.io, 2026-09-04), so the policy is discoverable by humans and not by machines. program: published: true url: https://ballerina.io/security-policy/ http_status: 200 contact: security@ballerina.io pgp: fingerprint: AC48 3C56 C0A0 6020 4BBE F3E4 182F 3F21 255F CCE9 keyserver: https://keys.openpgp.org acknowledgement_window: 24 hours process: - Private report to security@ballerina.io, encrypted with the published PGP key if desired. - Acknowledgement within 24 hours, followed by a detailed response and next steps. - Confirmation of true positives, fix development, and an immediate release where warranted. - Public disclosure only after mitigation; reporters are asked not to disclose before then. bounty: exists: true name: WSO2 Security Reward and Acknowledgement Program scope: - compiler - runtime - CLI tooling - standard library - VS Code extension - website note: Recognition/reward program run by WSO2 rather than a HackerOne/Bugcrowd-hosted bounty. advisories: location: GitHub security advisories on the ballerina-platform repositories example: CVE-2021-32700 well_known_security_txt: false gaps: - >- A three-line /.well-known/security.txt on ballerina.io (Contact, Encryption, Policy) would make this existing policy machine-readable at zero content cost.