specification: API Commons VulnerabilityDisclosure specificationVersion: '0.1' provider: Federal Student Aid providerId: federal-student-aid generated: '2026-09-09' method: searched source: https://www.ed.gov/about/ed-overview/required-notices/vulnerability-disclosure-policy modified: '2026-09-09' description: >- Federal Student Aid is an office of the U.S. Department of Education and is covered by the Department's published Vulnerability Disclosure Policy, issued under CISA Binding Operational Directive 20-01. The policy's scope is written system-wide rather than domain-by-domain, so StudentAid.gov, FSA Partner Connect and the College Scorecard docs host all fall inside it without being named. published: true program_type: coordinated-disclosure bug_bounty: false bug_bounty_note: >- No paid bounty. This is a federal coordinated-disclosure program with legal safe harbour, not a HackerOne/Bugcrowd/Intigriti engagement. policy: url: https://www.ed.gov/about/ed-overview/required-notices/vulnerability-disclosure-policy status: 200 probed: '2026-09-09' note: >- https://www.ed.gov/vulnerability-disclosure-policy 301-redirects here. authority: CISA Binding Operational Directive 20-01 scope: covered: >- "All internet-accessible, public facing, systems or services of the Department" excluded: Non-federal vendor systems. named_domains: [] named_domains_note: >- The policy asserts coverage by class, not by hostname; no domain list is published, so inclusion of studentaid.gov is inferred from the class rather than stated. reporting: portal: https://usdeptofed.responsibledisclosure.com/hc/en-us/requests/new email: OCIO_VDP@ed.gov email_purpose: questions about the policy anonymous_reports: true safe_harbor: provided: true quote: >- "For those security research activities conducted in accordance with the restrictions and guidelines set forth in this policy... the Department will deem such activities authorized and (1) will not recommend or pursue legal action" timelines: acknowledgement: 3 business days embargo: 90 calendar days embargo_quote: >- "the Department requests that security researchers refrain from sharing information about discovered vulnerabilities for ninety (90) calendar days after receiving an acknowledgement of receipt" security_txt: published: false probed: - url: https://studentaid.gov/.well-known/security.txt status: 404 - url: https://collegescorecard.ed.gov/.well-known/security.txt status: 404 - url: https://fsapartners.ed.gov/.well-known/security.txt status: 404 - url: https://api.data.gov/.well-known/security.txt status: 404 - url: https://www.ed.gov/.well-known/security.txt status: 403 note: >- The policy exists as an HTML page but is not advertised at any RFC 9116 /.well-known/security.txt on any host this record knows. A researcher who looks where the standard says to look finds nothing — that is the actionable gap here, and it is cheap for the Department to close.