generated: '2026-09-05' method: searched probe: true source: https://www.cfa.gov/vulnerability-disclosure-policy note: >- The CFA publishes a full CISA-aligned agency Vulnerability Disclosure Policy at a non-standard path (/vulnerability-disclosure-policy), which is why the mechanical probe-security-programs.py sweep — which checks /vulnerability-disclosure, /responsible-disclosure, /security and /.well-known/security.txt — recorded vdp=none. Found by walking the agency sitemap.xml. No /.well-known/security.txt is served (404), so the policy is human-discoverable only. policy: - https://www.cfa.gov/vulnerability-disclosure-policy contact: - security@cfa.gov - webmaster@cfa.gov safe_harbor: true anonymous_reports_accepted: true bug_bounty: false bounty_note: >- "you acknowledge that you have no expectation of payment and that you expressly waive any future pay claims against the U.S. Government" — quoted from the policy. coordination: body: Cybersecurity and Infrastructure Security Agency (CISA) note: >- Findings affecting all users of a product, not solely the CFA, may be shared with CISA and handled under their coordinated vulnerability disclosure process. response_targets: - {milestone: acknowledgement, within: 3 business days} - {milestone: initial assessment and validity confirmation, within: 7 business days} - {milestone: reporter notified of resolution outcome, within: 90 days} out_of_scope: - physical testing (office access, open doors, tailgating) - social engineering (phishing, vishing) - non-technical vulnerability testing - third-party vendor systems (report to the vendor) evidence: - source: https://www.cfa.gov/vulnerability-disclosure-policy kind: agency vulnerability disclosure policy page http_status: 200 fetched: '2026-09-05' - source: https://www.cfa.gov/website-policies kind: policy hub linking the VDP http_status: 200 fetched: '2026-09-05' - source: https://www.cfa.gov/.well-known/security.txt kind: RFC 9116 probe http_status: 404 fetched: '2026-09-05'