generated: '2026-09-10' method: searched probe: true source: https://www.justice.gov/jmd/vulnerability-disclosure-policy ownership_note: >- The Foreign Claims Settlement Commission runs no host of its own — its entire public surface is https://www.justice.gov/fcsc. The disclosure policy recorded here is the Department of Justice Vulnerability Disclosure Policy, which states it applies to "all DOJ-managed systems and services that are accessible from the Internet. This includes the registered domain name - DOJ.gov", and it is the policy the FCSC's own page footer links to. It therefore covers FCSC's systems; it is not an FCSC-authored document, and the department-wide record is all/department-of-justice. policy: - https://www.justice.gov/jmd/vulnerability-disclosure-policy contact: - Responsible_Disclosure@usdoj.gov - https://fb6d331c8f530081fa81e12d81678ff8.responsibledisclosure.com/ program: type: coordinated-disclosure bounty: false intake: DOJ VDP reporting portal (responsibledisclosure.com) or email acknowledgement_target: three business days reporter_obligation: notify DOJ OCIO within 72 hours of discovering a vulnerability security_txt: served: false note: >- /.well-known/security.txt returned 404 on www.justice.gov on 2026-09-10 (see well-known/foreign-claims-settlement-commission-well-known.yml). The policy is published as an HTML page only; no RFC 9116 document points at it. evidence: - source: https://www.justice.gov/jmd/vulnerability-disclosure-policy kind: disclosure-policy-page http_status: 200 fetched: '2026-09-10' - source: https://www.justice.gov/fcsc kind: footer-link-to-policy http_status: 200 fetched: '2026-09-10' - source: https://www.justice.gov/.well-known/security.txt kind: security.txt http_status: 404 fetched: '2026-09-10'