generated: '2026-09-09' method: searched probe: true source: https://www.fmshrc.gov/content/vulnerability-disclosure-policy provider: Federal Mine Safety and Health Review Commission providerId: federal-mine-safety-and-health-review-commission description: >- FMSHRC publishes a Vulnerability Disclosure Policy dated January 2024, in the form required of federal civilian agencies by CISA Binding Operational Directive 20-01. The policy is linked from the site footer as an HTML landing page whose body is a single link to a Section 508-remediated PDF; the substance lives in the PDF. It grants safe harbor for good-faith research, names an in-scope system, states acknowledgement timelines, and accepts anonymous reports. It was NOT discoverable by machine: no /.well-known/security.txt is served on any FMSHRC host (all 404), so the automated security-programs probe found nothing and this was located by reading the site navigation. Publishing an RFC 9116 security.txt pointing at this same policy would make it machine-findable at no cost. policy: - https://www.fmshrc.gov/content/vulnerability-disclosure-policy - https://www.fmshrc.gov/sites/default/files/Vulnerability%2520Disclosure%2520Policy_508.pdf policy_dated: '2024-01' contact: - mailto:ITSecurity@fmshrc.gov - https://bugcrowd.com/engagements/fcc-vdp contact_note: >- The policy text reads: "We accept vulnerability reports through our bugcrowd program (https://bugcrowd.com/fcc-vdp) and questions can be directed to ITSecurity@fmshrc.gov." That Bugcrowd engagement slug is the FEDERAL COMMUNICATIONS COMMISSION's program (fcc-vdp), not an FMSHRC one — https://bugcrowd.com/fmshrc returns 404 while https://bugcrowd.com/fcc-vdp resolves 200 to https://bugcrowd.com/engagements/fcc-vdp. Recorded verbatim as published, flagged as an apparent copy error in the agency's own document. A researcher following the published link would file against a different agency. The email address is the reliable channel. anonymous_reports_accepted: true safe_harbor: true safe_harbor_terms: - Good-faith research conducted under the policy is considered authorized; FMSHRC will not recommend or pursue legal action related to it. - If a third party initiates legal action for activity conducted in accordance with the policy, FMSHRC will make the authorization known. sla: acknowledgement: within 3 business days when contact information is shared acknowledgement_alt: >- The policy states both "within 5 business days" (reporting section) and "within 3 business days" (what-you-can-expect section); both figures are quoted as published. in_scope: - fmshrc.gov out_of_scope: - Any service not expressly listed, including connected services. - Vulnerabilities in vendor systems, which are to be reported to the vendor under the vendor's own disclosure policy. prohibited_test_methods: - Network denial of service (DoS/DDoS) or any test that impairs access to or damages a system or data. - Physical testing (office access, open doors, tailgating). - Social engineering (phishing, vishing) or other non-technical vulnerability testing. researcher_guidelines: - Notify FMSHRC as soon as possible after discovering a real or potential security issue. - Avoid privacy violations, degradation of user experience, disruption to production systems, and destruction or manipulation of data. - Use exploits only to the extent necessary to confirm a vulnerability's presence; do not exfiltrate data, establish persistent command-line access, or pivot to other systems. - Allow reasonable time to resolve the issue before public disclosure. - Do not submit a high volume of low-quality reports. - Stop testing and notify immediately on encountering sensitive data; do not disclose it to anyone else. onward_sharing: >- Reports affecting all users of a product or service, not solely FMSHRC, may be shared with the Cybersecurity and Infrastructure Security Agency (CISA). Reporter name and contact information are not shared without express permission. bug_bounty: published: false platforms_checked: [HackerOne, Bugcrowd, Intigriti] note: >- No FMSHRC bounty program exists. The Bugcrowd link in the policy points at the FCC's engagement; see contact_note. This is a disclosure program, not a paid bounty. security_txt: served: false probed: - https://www.fmshrc.gov/.well-known/security.txt - https://fmshrc.gov/.well-known/security.txt - https://fmshrc-ecms.entellitrak.com/.well-known/security.txt status: 404 evidence: - url: https://www.fmshrc.gov/content/vulnerability-disclosure-policy status: 200 kind: disclosure-policy landing page (live probe) - url: https://www.fmshrc.gov/sites/default/files/Vulnerability%2520Disclosure%2520Policy_508.pdf status: 200 kind: disclosure policy PDF, application/pdf, 261889 bytes (live probe, text extracted) - url: https://bugcrowd.com/engagements/fcc-vdp status: 200 kind: bounty platform page named in the policy (belongs to the FCC) - url: https://bugcrowd.com/fmshrc status: 404 kind: control probe — no FMSHRC Bugcrowd engagement exists - url: https://www.fmshrc.gov/.well-known/security.txt status: 404 kind: security.txt (live probe) maintainers: - FN: Kin Lane email: kin@apievangelist.com