generated: '2026-09-07' method: searched probe: true source: https://www.state.gov/bureau-of-diplomatic-technology/vulnerability-disclosure-policy summary: >- The Department of State publishes a full Vulnerability Disclosure Policy issued by the Bureau of Diplomatic Technology, with explicit safe-harbor authorization, a named scope, a coordinated disclosure window and two intake channels including a HackerOne program. It is a genuine, current disclosure program — it is simply not discoverable where a machine would look for it: there is no /.well-known/security.txt on any State host, and the path 301s to an unrelated page (see well-known/department-of-state-well-known.yml). policy: - https://www.state.gov/bureau-of-diplomatic-technology/vulnerability-disclosure-policy contact: - vdpsubmission@state.gov bug_bounty: platform: HackerOne url: https://hackerone.com/us-department-of-state?type=team paid: false note: >- Listed as a team page, used as the submission portal. The policy does not offer monetary awards; it offers legal authorization for good-faith research. submission_channels: - kind: hackerone url: https://hackerone.com/us-department-of-state?type=team - kind: anonymous-web-form url: https://hackerone.com/6b30fb0b-5a38-49c4-b23b-442da04cfb63/embedded_submissions/new note: Embedded HackerOne form; the policy offers it for anonymous reporting. - kind: email target: vdpsubmission@state.gov note: Also the address for scope questions and policy feedback. scope: in_scope: >- "all Department internet accessible systems and services to include those specified at HackerOne" — quoted verbatim from the policy. out_of_scope: >- Vendor systems. The policy directs those reports to the vendor's own disclosure policy. escalation: >- Researchers unsure whether a system is in scope are told to contact vdpsubmission@state.gov, or the security contact for the domain in the .gov WHOIS at https://domains.dotgov.gov/dotgov-web/registration/whois.xhtml, before starting. safe_harbor: >- "If you make a good faith effort to comply with this policy during your security research, we will consider your research to be authorized and we will work with you to understand and resolve the issue quickly, and Department of State will not recommend or pursue legal action related to your research." The Department also commits to making that authorization known to a third party who initiates action against a compliant researcher. timelines: acknowledgement: 3 business days when contact information is shared coordinated_disclosure_window: typically 100 calendar days before public disclosure prohibited_testing: - Network denial or distributed denial of service (DoS/DDoS) and anything else that impairs access or damages data - Physical testing (office access, open doors, tailgating) - Social engineering (phishing, vishing) and other non-technical testing - High volumes of low-quality reports - Using an exploit beyond confirming presence — no exfiltration, no command-line access, no persistence, no pivoting onward_sharing: >- Reports affecting all users of a product may be shared with CISA and handled under its coordinated vulnerability disclosure process (https://www.cisa.gov/coordinated-vulnerability-disclosure-process), and with other U.S. Government entities where required by law. The Department commits not to share a reporter's name or contact information without express permission. history: - version: '1.0' date: '2021-03-04' description: First issuance - version: '1.1' date: '2022-12-01' description: Updated form for submitting a vulnerability report regime: directive: CISA Binding Operational Directive 20-01 note: >- BOD 20-01 requires federal civilian agencies to publish a VDP and to serve it at /.well-known/security.txt. The Department satisfies the policy half and not the discovery half. evidence: - source: https://www.state.gov/bureau-of-diplomatic-technology/vulnerability-disclosure-policy kind: disclosure-policy-page http_status: 200 fetched: '2026-09-07' - source: https://hackerone.com/us-department-of-state?type=team kind: bug-bounty-platform http_status: 200 fetched: '2026-09-07' - source: https://www.state.gov/.well-known/security.txt kind: security.txt http_status: 301 fetched: '2026-09-07' note: Redirects to /state-gov-website-modernization/ — no RFC 9116 document is served.