generated: '2026-09-07' method: searched source: >- https://www.dow.com/.well-known/security.txt (RFC 9116, HTTP 200) and the policy it names, https://www.synack.com/vdp/dow/ (HTTP 200) program: name: Dow Vulnerability Disclosure Program operator: Synack, Inc. hosted_by: synack type: vulnerability-disclosure bounty: false bounty_note: >- Not a bug bounty. The program guidelines require researchers to "not request compensation for time and materials or vulnerabilities discovered"; recognition is via an Acknowledgments page. safe_harbor: true safe_harbor_note: >- "Synack commits that, if we conclude, in our sole discretion, that a security vulnerability submitted through our Site complies with the Terms of Use, the applicable Scope and Rules of Engagement and the applicable Responsible Disclosure Guidelines, Synack will not bring a private action against you." submission: Web form on the Synack VDP page (no email intake for findings) policy: - https://www.synack.com/vdp/dow/ contact: - mailto:vulnerabilitydisclosure@dow.com scope: in_scope: - '*.dow.com' - '*.midlandresolution.com' - '*.rohmandhaas.com.tr' - '*.rohmhaaskimyasanayi.com.tr' - '*.triverconservation.com' - '*.univation.com' - '*.dorinco.com' out_of_scope_note: >- "All other Dow systems and services are out of scope for the purpose of the Program." security_txt: served: true file: well-known/dow-chemical-security.txt hosts: - www.dow.com - dow.com - legal.dow.com - corporate.dow.com fields_present: - Contact - Policy fields_absent: - Expires - Encryption - Acknowledgments - Preferred-Languages - Canonical note: >- RFC 9116 makes Expires REQUIRED. Dow's file omits it, so a consumer cannot tell whether the document is current. Otherwise the file is well-formed and served identically on all four hosts. evidence: - source: https://www.dow.com/.well-known/security.txt kind: security.txt (live fetch, HTTP 200, text/plain) fetched: '2026-09-07' - source: https://www.synack.com/vdp/dow/ kind: disclosure policy page (HTTP 200) fetched: '2026-09-07'