generated: '2026-09-05' method: searched probe: true source: https://www.state.gov/bureau-of-diplomatic-technology/vulnerability-disclosure-policy note: >- The Bureau of Consular Affairs does not run its own disclosure program. It is covered by the U.S. Department of State Vulnerability Disclosure Policy, published by the Bureau of Diplomatic Technology, which states it "applies to all Department internet accessible systems and services" — that includes travel.state.gov and cadatacatalog.state.gov. Reports are taken through HackerOne or an anonymous web form. Recorded at the Department level because that is the level at which the bureau's systems are actually in scope. policy: - https://www.state.gov/bureau-of-diplomatic-technology/vulnerability-disclosure-policy - https://hackerone.com/us-department-of-state contact: - vdpsubmission@state.gov program: platform: HackerOne handle: us-department-of-state url: https://hackerone.com/us-department-of-state submission_url: https://hackerone.com/6b30fb0b-5a38-49c4-b23b-442da04cfb63 bounty: false scope: >- All Department of State internet accessible systems and services, including those specified on the HackerOne program page. Vulnerabilities in vendor systems are explicitly out of scope. disclosure: coordinated: true wait_before_public_disclosure: '100 calendar days' acknowledgement_target: '3 business days (when contact information is shared)' escalation: >- Findings affecting all users of a product or service may be shared with CISA and handled under its coordinated vulnerability disclosure process. security_txt: served: false note: >- No /.well-known/security.txt is served on any bureau host. www.state.gov 301s the path and the followed URL returns a 403 interstitial; travel.state.gov and cadatacatalog.state.gov 403 every path behind Cloudflare. See well-known/bureau-of-consular-affairs-well-known.yml. evidence: - source: https://www.state.gov/bureau-of-diplomatic-technology/vulnerability-disclosure-policy http_status: 200 fetched: '2026-09-05' kind: disclosure-policy quotes: - 'Provide us a reasonable amount of time (typically 100 calendar days) to resolve the issue before coordinated disclosure.' - "This policy applies to all Department internet accessible systems and services to include those specified at HackerOne." - 'Questions regarding this policy may be sent to vdpsubmission@state.gov.' - source: https://hackerone.com/us-department-of-state http_status: 200 fetched: '2026-09-05' kind: bug-bounty-platform