generated: '2026-09-05' method: searched source: https://www.opm.gov/vulnerability-disclosure-policy/ provider: Chief Human Capital Officers Council providerId: chief-human-capital-officers ownership_note: >- This policy is published by the U.S. Office of Personnel Management, the agency that chairs the CHCO Council and hosts its entire web presence. It is recorded here because the policy's own Scope section names BOTH chcoc.gov and opm.gov explicitly — the two domains that serve this record — so it is the vulnerability disclosure program that actually governs the Council's public surface, not a neighbouring agency's policy borrowed by association. program: name: OPM Vulnerability Disclosure Policy url: https://www.opm.gov/vulnerability-disclosure-policy/ status: active type: vulnerability-disclosure-policy bounty: false bounty_note: OPM states it does not offer compensation for identifying or reporting vulnerabilities. platform: Bugcrowd platform_url: https://bugcrowd.com/opm-vdp authority: CISA Binding Operational Directive 20-01 (federal agency VDP requirement) contacts: - type: email value: opm-vdp@submit.bugcrowd.com purpose: Submit a vulnerability report - type: web value: https://bugcrowd.com/opm-vdp purpose: Submit a vulnerability report - type: email value: vulnerabilitydisclosure@opm.gov purpose: Ask whether a system or endpoint is in scope before testing scope: in_scope: - External-facing OPM registered and managed .gov domains and all sub-domains - chcoc.gov - opm.gov - applicationmanager.gov - cybercareers.gov - employeeexpress.gov - feb.gov - federaljobs.gov - fedjobs.gov - fedshirevets.gov - fsafeds.gov - golearn.gov - governmentjobs.gov - pac.gov - pmf.gov - telework.gov - unlocktalent.gov - usajobs.gov - usalearning.gov - usastaffing.gov out_of_scope: - Testing of third-party services OPM uses (non-public data published on them is in scope; testing them is not) - Any service not expressly listed in the policy, including connected services - Vulnerabilities in non-federal vendor systems (report to the vendor) safe_harbor: present: true statement: >- OPM will consider good-faith research conducted within this policy to be authorized and will not pursue legal action against authorized research. timelines: acknowledgement: Within 5 business days, when contact information is provided initial_response: Within 3 business days disclosure_embargo: Researchers keep findings confidential for up to 90 calendar days after notifying OPM rules_of_engagement: prohibited: - Denial of service / resource exhaustion testing - Physical testing of federal or contractor facilities - Social engineering, phishing, vishing, unsolicited email - Introducing malicious software or code - Testing that deletes, alters, shares, retains or destroys data - Exfiltrating data, establishing command-line access, privilege escalation, persistence, or pivoting - Testing third-party applications or services that integrate with agency systems required: - Cease testing and notify OPM immediately on discovering a vulnerability - Cease testing and notify OPM immediately on discovering exposed non-public data or PII - Purge any stored agency non-public data upon reporting gaps: - >- OPM does not serve an RFC 9116 /.well-known/security.txt on opm.gov, chcoc.gov or www.opm.gov — the policy is a web page only, so an automated agent cannot discover it. Probed 2026-09-05: https://www.opm.gov/.well-known/security.txt returned 503 with an HTML error body; https://www.chcoc.gov/.well-known/security.txt returned 301 to https://www.opm.gov/chcoc. evidence: - url: https://www.opm.gov/vulnerability-disclosure-policy/ http_status: 200 fetched: '2026-09-05' note: Scope section names chcoc.gov and opm.gov verbatim - url: https://www.opm.gov/.well-known/security.txt http_status: 503 fetched: '2026-09-05' note: HTML "Unexpected Error" page, not a security.txt maintainers: - FN: Kin Lane email: kin@apievangelist.com