generated: '2026-09-10' method: searched probe: true source: https://bugcrowd.com/engagements/usda-vdp note: >- FAS itself publishes no security or disclosure page. What covers it is the parent department's program: USDA runs a department-wide Vulnerability Disclosure Policy, operated as a Bugcrowd engagement. fas.usda.gov and apps.fas.usda.gov are usda.gov subdomains, so the agency inherits the department's policy the way a brand inherits its parent's — this is the same different-domain justification the pipeline accepts for a parent brand, stated explicitly rather than assumed. program: type: vulnerability-disclosure-policy operator: Bugcrowd managed_by: U.S. Department of Agriculture bounty: false bounty_note: 'a VDP, not a paid bug bounty — Bugcrowd classifies the engagement as "Vulnerability Disclosure"' policy: - https://www.usda.gov/vulnerability-disclosure-policy - https://bugcrowd.com/engagements/usda-vdp contact: [] contact_note: >- Reports are submitted through the Bugcrowd engagement, not to an email address. No security@ address is published for FAS or for USDA, and no /.well-known/security.txt is served on any host — see well-known/foreign-agricultural-service-well-known.yml. The RFC 9116 discovery path a scanner would look for does not exist, which is why this program is findable only by search. evidence: - source: https://bugcrowd.com/engagements/usda-vdp kind: bug-bounty-platform-page http_status: 200 fetched: '2026-09-10' detail: >- Live and public. Page title "Vulnerability Disclosure: United States Department of Agriculture: Vulnerability Disclosure Program"; og:title "United States Department of Agriculture: Vulnerability Disclosure Program | Bugcrowd"; og:description "Learn more about U.S. Federal Government's Vulnerability Disclosure engagement powered by Bugcrowd". Reached via a 301 from the older https://bugcrowd.com/usda-vdp path. - source: https://www.usda.gov/vulnerability-disclosure-policy kind: policy-page http_status: 403 fetched: '2026-09-10' detail: >- NOT dead — an Akamai edge block on our crawler. The page returns the standard "Access Denied" edgesuite body for any request from this client, as does every other www.usda.gov path including the site root, while a browser-header request to the root succeeded once in the same session. The URL is the one USDA itself publishes as its VDP location. Recorded as live-but-unreadable rather than credited as read. - source: /.well-known/security.txt on www.fas.usda.gov and www.usda.gov kind: negative http_status: 404 fetched: '2026-09-10' detail: real origin 404 on both hosts — no RFC 9116 file scope: stated: USDA department-wide fas_assets_verified: false detail: >- The Bugcrowd brief carrying the in-scope asset list returned 301 to our fetcher and was not read, so it is NOT asserted here that fas.usda.gov or apps.fas.usda.gov appear on it by name. What is asserted is what is verifiable: USDA operates a department-wide VDP, and these are USDA hosts. A researcher should read the brief for the current asset list.