generated: '2026-08-02' method: searched probe: true source: https://bishopfox.com/vulnerability-disclosure-policy policy: - https://bishopfox.com/vulnerability-disclosure-policy - https://bishopfox.com/privacy-statement report_url: https://bishopfox.com/report-issue contact: - security@bishopfox.com - contact@bishopfox.com security_txt: url: https://bishopfox.com/.well-known/security.txt http_status: 200 file: well-known/bishop-fox-security.txt fields: contact: security@bishopfox.com policy: https://bishopfox.com/privacy-statement expires: '2025-12-31T00:00:00-08:00' notes: >- The Expires field is in the past as observed on 2026-08-02, and the Policy field points at the privacy statement rather than the vulnerability disclosure policy page. Both are RFC 9116 hygiene defects worth reporting back to the provider. disclosure_policy: scope: >- Two-sided. The policy covers coordinated disclosure of vulnerabilities Bishop Fox researchers find in third-party vendor products, and reporting of issues found in Bishop Fox's own assets. reporting_channel: https://bishopfox.com/report-issue standard_deadline_days: 90 zero_day_deadline_days: 7 patch_extension_days: 14 cert_cc_escalation_days: 15 cve_assignment: true safe_harbor: not-stated bug_bounty: program: none-published platforms: [] evidence: - source: https://bishopfox.com/vulnerability-disclosure-policy kind: disclosure-policy-page http_status: 200 fetched: '2026-08-02' - source: https://bishopfox.com/.well-known/security.txt kind: security.txt http_status: 200 fetched: '2026-08-02'