generated: '2026-09-14' method: searched source: https://www.boozallen.com/e/about-content/cyber-security-concern-reporting.html — fetched 2026-09-14 (HTTP 200) program: published: true type: vulnerability-disclosure name: Booz Allen Hamilton Cyber Incident Response Team (BAH-CIRT) url: https://www.boozallen.com/e/about-content/cyber-security-concern-reporting.html http_status: 200 contact_email: BAH_CIRT@bah.com web_form: true encryption: 'PGP supported — "Booz Allen Hamilton CIRT supports encrypted emails via PGP"' pgp_key_url: null submission_guidance: - a brief summary of the compromised or at-risk information - the email, domain name or IP address involved - how the activity was detected - contact information for a reply bounty: false safe_harbor_stated: false security_txt: published: false note: >- /.well-known/security.txt returns the site's 170KB SPA shell on both www.boozallen.com and boozallen.com — a catch-all 200, not a document. This is the single cheapest fix available to the firm: it already runs a named CIRT with a published address, and one RFC 9116 file at /.well-known/security.txt would make that machine-discoverable. open_source_disclosure: published: true mechanism: GitHub private security advisories repos: - https://github.com/boozallen/strands-base-agent/blob/develop/SECURITY.md - https://github.com/boozallen/foundry-agent-packages/blob/develop/SECURITY.md - https://github.com/boozallen/aissemble/blob/dev/SECURITY.md process: - 'Do not open a public issue for security vulnerabilities.' - 'Security tab -> "Report a vulnerability" -> submit a Draft Security Advisory.' response_targets: acknowledgement: within 3 business days initial_assessment: within 7 business days resolution: depends on severity; critical issues prioritized coordinated_disclosure: true credit: 'reporters credited (with permission) in release notes' unconfirmed: - url: https://hackerone.com/booz_allen_hamilton http_status: 200 finding: >- The URL resolves, but the response is HackerOne's JavaScript shell (2,299 bytes, no program content) and hackerone.com/booz_allen_hamilton.json returns 404. No program scope, policy or bounty status could be read, so nothing about a HackerOne program is asserted here.