generated: '2026-08-05' method: searched probe: true source: https://www.sifive.com/psirt-report-vulnerability description: >- SiFive runs a Product Security Incident Response Team (PSIRT) with a published Coordinated Vulnerability Disclosure policy. Note that the automated probe path missed it: SiFive serves no /.well-known/security.txt (404) and no /security page (404), and publishes the policy at the non-standard path /psirt-report-vulnerability, which was found by walking the sitemap. program: name: SiFive PSIRT type: coordinated-vulnerability-disclosure bug_bounty: false bug_bounty_note: 'SiFive states explicitly that it does not have a bounty program.' policy: - https://www.sifive.com/psirt-report-vulnerability contact: - psirt@sifive.com pgp: published: true fingerprint: '7419 9D2D 8492 0806 E6F2 9CB9 93EA DB99 09EE E744' note: 'Public key published on the policy page; reporters may also submit password-protected zip files.' standards: - {id: iso-iec-29147, name: 'ISO/IEC 29147 Vulnerability disclosure', adheres: true} - {id: iso-iec-30111, name: 'ISO/IEC 30111 Vulnerability handling processes', adheres: true} - {id: cvss, name: 'Common Vulnerability Scoring System', adheres: true} - {id: cve, name: 'Common Vulnerabilities and Exposures', adheres: true} report_requirements: - Affected SiFive product and version number - Vulnerability description with steps to reproduce and proof of concept - Impact assessment and any proposed remediation - Reporter name, organization and contact details - Any planned publication or presentation dates remediation_channels: [new release, patch, workaround, security advisory] recognition: acknowledgement_page: true note: 'Reporters may be recognized on the SiFive Acknowledgement page, with consent.' gaps: - >- No RFC 9116 security.txt at https://www.sifive.com/.well-known/security.txt (404), so automated scanners and agents cannot discover the PSIRT contact. Adding a security.txt with Contact and Policy pointing at psirt@sifive.com and /psirt-report-vulnerability would make an already-real program machine-discoverable. - >- No stated acknowledgement or remediation SLA — the policy says vulnerabilities are prioritized by severity and impact but names no response timeframes. evidence: - {source: 'https://www.sifive.com/psirt-report-vulnerability', kind: disclosure-policy, status: 200} - {source: 'https://www.sifive.com/.well-known/security.txt', kind: security.txt, status: 404} - {source: 'https://www.sifive.com/security', kind: security-page, status: 404} - {source: 'https://www.sifive.com/sitemap.xml', kind: sitemap, status: 200, note: 'where the PSIRT URL was found'} x-evidence: fetched: '2026-08-05' url: https://www.sifive.com/psirt-report-vulnerability http_status: 200