generated: '2026-09-12' method: searched source: >- https://www.ginniemae.gov/site-policies/ginnie-mae-vulnerability-disclosure-policy (HTTP 200). The page is rendered client-side; its text was read through the site's own API at https://www.ginniemae.gov/api/v1/node/web_page/0a8f5c06-6e9f-4b49-a3a7-13c61fadd98a and the seven paragraph--accordion resources it references. Fetched 2026-09-12. provider: Ginnie Mae providerId: ginnie-mae published: true policy_url: https://www.ginniemae.gov/site-policies/ginnie-mae-vulnerability-disclosure-policy program_type: coordinated-vulnerability-disclosure shaped_by: CISA Binding Operational Directive 20-01 bug_bounty: offered: false detail: >- Explicitly not. The policy asks researchers not to request compensation for time, materials or vulnerabilities discovered. No HackerOne, Bugcrowd or Intigriti program was found. reporting: channel: email address: ginniemaevdp@hud.gov anonymous_reports_accepted: true preferred_language: English requested_content: - Location of the vulnerability and the potential impact of exploitation - Detailed reproduction steps, with proof-of-concept scripts or screenshots commitments: acknowledgement: 3 business days, when the researcher shares contact information coordination: >- Ginnie Mae commits to coordinating as openly and as quickly as possible, and will not share the reporter's name or contact information without express permission. onward_disclosure: >- Findings that affect all users of a product or service, not solely Ginnie Mae, may be shared with CISA and handled under its coordinated vulnerability disclosure process. scope: in_scope: - '*.ginniemae.gov' out_of_scope: - Any connected service not expressly listed - Vulnerabilities in non-federal vendor systems, which go to the vendor's own policy note: >- Ginnie Mae states it will increase the scope of this policy over time, and invites researchers to ask at ginniemaevdp@hud.gov before testing anything they are unsure about, or to use the security contact in the .gov WHOIS record for the domain. safe_harbour: present: true text_summary: >- "If you make a good faith effort to comply with this policy during your security research, we will consider your research to be authorized, we will work with you to understand and resolve the issue quickly, and Ginnie Mae will not recommend or pursue legal action related to your research." authorized_activity: - Testing to detect a vulnerability or identify an indicator related to a vulnerability - Sharing with, or receiving from, Ginnie Mae information about a vulnerability prohibited_test_methods: - Network denial of service (DoS/DDoS) or any test that impairs access to, or damages, a system or data - Physical testing, social engineering, phishing or vishing, and other non-technical testing - Full red-team penetration testing involving unauthorized access to servers - Social engineering or phishing of customers or employees - Theoretical vulnerabilities - Informational disclosure of non-sensitive data - Low-impact session management issues - Self XSS researcher_obligations: - Notify the agency as soon as possible after discovering a real or potential issue - Avoid privacy violations, degradation of user experience, disruption to production systems, and destruction or manipulation of data - Do no harm; do not exploit a vulnerability beyond the minimum needed to prove it exists - Do not intentionally access the content of communications, data or information beyond what is needed to prove the vulnerability - Do not exfiltrate data under any circumstances - Do not compromise the privacy or safety of Ginnie Mae personnel, contractors, affiliates or third parties security_txt: published: false evidence: >- https://www.ginniemae.gov/.well-known/security.txt returns HTTP 200 with content-type text/html — the Angular application shell, not an RFC 9116 document. Probed 2026-09-12. This is the single cheapest improvement available to Ginnie Mae here: the policy, the contact address and the preferred language already exist and a security.txt would make them machine-discoverable at the location scanners actually look.