generated: '2026-09-07' method: searched source: https://www.hud.gov/vulnerability-disclosure-policy provider: Fair Housing and Equal Opportunity providerId: fair-housing-and-equal-opportunity note: >- FHEO is a program office inside HUD and does not publish its own security policy. The policy recorded here is HUD's department-wide Vulnerability Disclosure Policy, which states its scope as "all HUD systems and services" — which covers the FHEO ArcGIS feature services and the AFFH-T services in this record. Inherited from the parent, not authored by FHEO. program: published: true url: https://www.hud.gov/vulnerability-disclosure-policy http_status: 200 fetched: '2026-09-07' title: Vulnerability Disclosure Policy document: HUD Handbook 2400.45 REV 2.0 effective: '2023-06-21' contact: VDP@hud.gov contact_note: >- Published on the policy page behind Cloudflare email obfuscation; decoded from the page's data-cfemail attribute on 2026-09-07. anonymous_reports_accepted: true reporting_template: Appendix A of the policy (optional, not required) acknowledgement_sla: three (3) business days, when contact information is shared remediation_sla: null remediation_note: >- No fixed remediation deadline is stated; HUD commits to working "as quickly as possible" and to agreeing a reasonable disclosure period with the reporter. safe_harbor: true safe_harbor_text: >- "If you make a good faith effort to comply with this policy during your security research, HUD will consider your research to be authorized." bug_bounty: false bug_bounty_platform: null coordinated_disclosure: true disclosure_requires_authorization: true scope: in_scope: - All HUD systems and services out_of_scope: - HUD vendor systems (report directly to the vendor) testing_restrictions: - >- No testing of www.ginniemae.gov, https://bulk.ginniemae.gov/ or https://my.ginniemae.gov/webcenter/portal/public during the first ten (10) business days of any month. - No denial-of-service testing. - No social engineering or spear phishing of HUD personnel or contractors. - No exfiltration of data from HUD systems. references: - name: CISA Coordinated Vulnerability Disclosure Process url: https://www.cisa.gov/coordinated-vulnerability-disclosure-process security_txt: published: false note: >- /.well-known/security.txt returns HTTP 404 on www.hud.gov, hud.gov, www.huduser.gov, egis.hud.gov and hudgis-hud.opendata.arcgis.com. The policy exists only as an HTML page, so a machine cannot find it from the host root. maintainers: - FN: Kin Lane email: kin@apievangelist.com