generated: '2026-08-04' method: searched probe: true source: https://emeritus.org/reporting-a-vulnerabilities/ policy: - https://emeritus.org/reporting-a-vulnerabilities/ contact: - Security@Emeritus.org - https://vdp.emeritus.org/ submission_portal: https://vdp.emeritus.org/ bug_bounty: false bug_bounty_note: 'Published verbatim on the policy page: "Emeritus do not operate a bug bounty or hall of fame programme."' safe_harbor: not-stated security_txt: false security_txt_note: No /.well-known/security.txt is served on eruditus.com, emeritus.org or admissions.emeritus.org (all HTTP 404 on 2026-08-04). The disclosure policy is a linked HTML page in the site footer rather than an RFC 9116 document. requirements: - Reports must be submitted in English. - Reports must include proof-of-concept or sufficient reproduction detail. - Reports must identify the vulnerable target, describe the vulnerability, and describe how it can be exploited. - One vulnerability per report, unless chaining is required to demonstrate impact. - Exercise caution with personal data; no third-party attacks and no denial-of-service testing. - Do not disclose the vulnerability to others until Emeritus has resolved it, per the timeframes in their disclosure policy. commitments: - Emeritus commits to resolving submitted reports "as quickly as possible" — no concrete SLA is published. - Reports are treated confidentially; the finder's personal details are not shared with third parties without authorization, except where legally required. evidence: - source: https://emeritus.org/reporting-a-vulnerabilities/ kind: disclosure-policy-page http_status: 200 fetched: '2026-08-04' - source: https://vdp.emeritus.org/ kind: disclosure-submission-portal http_status: 200 fetched: '2026-08-04' - source: https://emeritus.org/policies/ kind: policy-index-linking-the-disclosure-page http_status: 200 fetched: '2026-08-04'