generated: '2026-09-07' method: searched source: https://www.fca.gov/required-notices/vulnerability-disclosure-policy program: present: true name: Farm Credit Administration Vulnerability Disclosure Policy policy_url: https://www.fca.gov/required-notices/vulnerability-disclosure-policy policy_status: 200 version: '1.0' first_issued: '2021-03-01' page_updated: '2022-09-01' mandate: >- Issued under DHS/CISA Binding Operational Directive 20-01. This is a federal-agency VDP, not a commercial bug bounty. security_txt: false security_txt_note: >- FCA publishes a conforming VDP page but does NOT serve /.well-known/security.txt on any of its hosts (all 404 or 500 — see well-known/farm-credit-administration-well-known.yml). BOD 20-01 expects the machine-readable pointer; this is the single cheapest fix available to FCA. bug_bounty: false bounty_note: >- Stated verbatim in the policy: "FCA does not issue payments for vulnerability reports." anonymous_reports_accepted: true contact: email: security_vdp@fca.gov method: email pgp_supported: false pgp_note: >- Policy states plainly: "We do not support PGP-encrypted emails." Reporters are asked to flag sensitive reports so FCA can arrange a more secure channel. scope_questions_email: security_vdp@fca.gov safe_harbor: present: true summary: >- Good-faith research complying with the policy is treated as authorized; FCA will not recommend or pursue legal action, and will make the authorization known if a third party initiates action. scope: in_scope_hosts: - www.fca.gov - apps.fca.gov - ww3.fca.gov - ww4.fca.gov - reports.fca.gov - wgis.fca.gov - ss.fca.gov - sso1.fca.gov - owa13.fca.gov out_of_scope: >- Anything not listed above, including connected services and vendor-operated systems (report those to the vendor). FCA states it will expand scope over time. note: >- This scope list is the most complete first-party inventory of FCA internet-facing hosts that exists anywhere on fca.gov, and it is what led this pass to wgis.fca.gov — the ArcGIS REST surface recorded in arcgis/. sso1.fca.gov did not resolve in DNS on 2026-09-07. prohibited_testing: - Network denial of service (DoS/DDoS) - Testing that could impair access to or damage a system or data - Deleting, altering, sharing, retaining or destroying FCA data - Data exfiltration, command-line access, persistence, or pivoting - Physical testing - Social engineering (phishing, vishing, whaling) - Use of malicious software - Testing third-party applications that integrate with or link to FCA systems disclosure: coordinated: true embargo_days: 90 embargo_basis: >- 90 calendar days from the date the reporter receives notice that FCA received the report. acknowledgement_sla_business_days: 5 shares_with: - Cybersecurity and Infrastructure Security Agency (CISA) - affected vendors researcher_identity_protected: true evidence: - url: https://www.fca.gov/required-notices/vulnerability-disclosure-policy status: 200 fetched: '2026-09-07' - url: https://www.fca.gov/.well-known/security.txt status: 404 fetched: '2026-09-07'