generated: '2026-09-06' method: searched source: https://www.eac.gov/vulnerability-disclosure-policy provider: Election Assistance Commission providerId: election-assistance-commission program: published: true name: EAC Vulnerability Disclosure Policy url: https://www.eac.gov/vulnerability-disclosure-policy http_status: 200 page_dated: '2025-12-23' shape: >- A full CISA BOD 20-01 style federal vulnerability disclosure policy — authorization (safe-harbour) statement, research guidelines, prohibited test methods, an explicit in-scope system list, reporting channels and coordination commitments. Fetched and read in full on 2026-09-06. safe_harbor: true safe_harbor_statement: >- "If you make a good faith effort to comply with this policy during your security research, we will consider your research to be authorized, will work with you to understand and resolve the issue quickly, and the EAC will not recommend or pursue legal action related to your research." coordinated_disclosure_window_days: 45 anonymous_reports_accepted: true pgp_supported: false scope: in_scope: - eac.gov and any subdomain of eac.gov - votebymail.gov - helpamericavote.gov out_of_scope: - Any system or service not expressly listed as in scope, including connected services - Vulnerabilities in vendor systems, which must go to the vendor's own disclosure process note: >- The JSON:API surface at https://www.eac.gov/jsonapi and the open-data catalog at https://www.eac.gov/data.json both sit on eac.gov and are therefore inside the published scope. prohibited_test_methods: - Network denial of service (DoS/DDoS) or any test that impairs access to or damages a system or data - Physical testing, social engineering (phishing/vishing) and other non-technical testing reporting: channels: - type: email note: >- A vulnerability-reporting mailbox is published on the policy page. The address is withheld from this artifact under the pipeline PII guardrail; read it from the policy page. - type: web_form url: https://www.eac.gov/vulnerability_disclosure_policy_Form http_status: 200 note: Preferred channel for particularly sensitive information (HTTPS form, no PGP support). escalation: - name: CISA coordinated vulnerability disclosure note: >- The EAC states it may share reports affecting all users of a product with CISA, handled under CISA's coordinated vulnerability disclosure process. Reporter name and contact are not shared without express permission. - name: CERT/CC government reporting form url: https://www.kb.cert.org/vuls/govreport/ note: Referred to for non-EAC federal systems with no published contact. bug_bounty: offered: false statement: >- "The EAC does not currently operate a bug bounty program. By submitting a vulnerability report, the submitter waives any and all claims to compensation." security_txt: served: false probed: - url: https://www.eac.gov/.well-known/security.txt status: 404 - url: https://eac.gov/.well-known/security.txt status: 404 - url: https://www.eac.gov/security.txt status: 404 finding: >- The policy exists and is complete, but it is not advertised at the RFC 9116 /.well-known/security.txt path on any EAC host, so no automated scanner or agent can discover it. Publishing a three-line security.txt pointing Policy: at the existing page would close this with no new content. maintainers: - FN: Kin Lane email: kin@apievangelist.com