generated: '2026-09-04' method: searched source: https://www.exim.gov/vulnerability-disclosure-policy summary: >- EXIM runs a real, managed Vulnerability Disclosure Program with published safe-harbour language, a defined scope, a dedicated mailbox and a Bugcrowd program page. It is not discoverable by machine: /.well-known/security.txt returns 404 on every exim.gov host, so the deterministic probe scores it as absent. This artifact was written from the policy page itself. disclosure: published: true policy_url: https://www.exim.gov/vulnerability-disclosure-policy http_status: 200 approved_on: '2021-03-25' program_name: EXIM Vulnerability Disclosure Program contact_email: VDP@exim.gov platform: name: Bugcrowd url: https://bugcrowd.com/exim-vdp http_status: 200 type: vulnerability-disclosure bounty: false note: >- A VDP, not a paid bug bounty. Federal agencies operate these under CISA BOD 20-01; no reward is offered or implied by the policy text. scope: in_scope: - Publicly available EXIM systems and services within the EXIM.gov domain - The registered domain name EXIM.gov out_of_scope: - Systems belonging to non-EXIM entities (report to that entity's own program) note: >- The policy states scope is subject to change and directs questions to VDP@exim.gov. Vendor-hosted tenants such as www.digitalarchives.exim.gov (OCLC CONTENTdm) and grow.exim.gov (HubSpot) sit on exim.gov names but are third-party operated — the "non-EXIM entities" carve-out plausibly reaches them, and the policy does not say. safe_harbor: true safe_harbor_text_verbatim: >- Efforts made in good faith to comply with this policy during all security research will be considered authorized. EXIM will work with the researcher to understand and quickly resolve issues and will not recommend or pursue legal action related to your research. Should legal action be initiated by a third party against the security researcher for research conducted in accordance with this policy, EXIM will reaffirm this authorization. security_txt: served: false probed: - url: https://www.exim.gov/.well-known/security.txt status: 404 - url: https://exim.gov/.well-known/security.txt status: 404 remedy: >- Serve an RFC 9116 file naming Contact: mailto:VDP@exim.gov, Policy: https://www.exim.gov/vulnerability-disclosure-policy and the Bugcrowd URL. Every fact it needs is already published; only the canonical path is missing.