generated: '2026-09-09' method: searched source: https://www.ftc.gov/policy-notices/vulnerability-disclosure-policy specification: API Commons Vulnerability Disclosure specificationVersion: '0.1' provider: Federal Trade Commission providerId: federal-trade-commission description: >- The FTC publishes a full Vulnerability Disclosure Policy with named scope, a safe-harbour statement, a stated acknowledgement window and a single intake channel on Bugcrowd. Fetched 2026-09-09, HTTP 200. program: published: true policy_url: https://www.ftc.gov/policy-notices/vulnerability-disclosure-policy policy_status: 200 intake: https://bugcrowd.com/ftc-vdp intake_status: 200 platform: Bugcrowd anonymous_reports_accepted: true bounty: false bounty_note: >- Verbatim from the policy — "you understand and agree that the FTC will not compensate you for reporting vulnerabilities." security_txt: false security_txt_note: >- /.well-known/security.txt returns 404 on www.ftc.gov and ftc.gov (probed 2026-09-09). The policy exists but is not machine-discoverable, so no SecurityTxt pointer is emitted. Publishing an RFC 9116 file pointing at this policy is the single cheapest improvement available to the agency here. scope: in_scope_domains: - '*.ftc.gov' - '*.consumer.gov' - '*.donotcall.gov' - '*.identitytheft.gov' - '*.militaryconsumer.gov' note: >- The published scope is a wildcard list of FTC-managed domains; api.ftc.gov is covered by *.ftc.gov. excluded_activities: - denial-of-service testing - social engineering - accessing or sharing personally identifiable information - testing that degrades confidentiality, integrity or availability safe_harbour: present: true text: >- The FTC "does not intend to recommend legal action against security research activities that we believe are authorized and represent a good-faith effort to follow the above policy." response_commitments: acknowledgement: 3 business days (when the reporter supplies contact information) disclosure: >- The FTC confirms the vulnerability where possible and communicates remediation progress, withholding details where disclosure would itself create risk. coordinated_disclosure_required: true regulatory_basis: - CISA Binding Operational Directive 20-01 - OMB M-20-32