generated: '2026-09-09' method: searched source: https://www.fhfa.gov/vulnerability-disclosure-policy provider: Federal Housing Finance Agency providerId: federal-housing-finance-agency description: >- FHFA operates a published vulnerability disclosure policy with an intake channel hosted on Bugcrowd. The policy is served as HTML at the URL above (HTTP 200, fetched 2026-09-09); FHFA does NOT publish a /.well-known/security.txt, so machine discovery of this program is not possible from the RFC 9116 path. program: published: true url: https://www.fhfa.gov/vulnerability-disclosure-policy status: 200 platform: Bugcrowd submission_url: https://bugcrowd.com/fhfa-vdp submission_status: 200 contact_email: domainsecurity@fhfa.gov anonymous_reports_accepted: true bug_bounty: false bounty_note: >- FHFA states plainly that it does not offer a bug bounty reward program and asks that research be conducted with no expectation of recognition or compensation. scope: in_scope: - domain: fhfa.gov note: all fhfa.gov domains - domain: mortgagetranslations.gov note: >- Listed in scope by the policy, but the host does not resolve in DNS as of 2026-09-09 — the policy scope is stale. out_of_scope: - Vendor-operated systems; the policy directs those reports to the vendor. safe_harbor: present: true statement: >- FHFA treats research conducted in compliance with the policy as authorized and states it "will not recommend or pursue legal action related to your research". If a third party initiates legal action, FHFA will make that authorization known. commitments: acknowledgement: within 5 business days disclosure_embargo: >- Researchers are asked to allow a minimum of 90 days for resolution before requesting public disclosure. transparency: >- FHFA commits to confirming whether a reported vulnerability exists and to maintaining an open dialogue about remediation. security_txt: served: false probed: - url: https://www.fhfa.gov/.well-known/security.txt status: 404 - url: https://fhfa.gov/.well-known/security.txt status: 404 remedy: >- Publishing the same Contact/Policy/Expires fields at /.well-known/security.txt would make this program machine-discoverable without changing anything about the program itself.