generated: '2026-07-28' method: searched probe: true source: >- https://www.faa.gov/web_policies/vulnerability_disclosure_policy (fetched verbatim 2026-07-28), https://www.transportation.gov/vulnerability-disclosure-policy (Akamai 403 to every automated client; text read from the Internet Archive snapshot 20260727163352), https://bugcrowd.com/engagements/usdot-vdp (HTTP 200 2026-07-28) summary: >- U.S. DOT runs TWO coordinated vulnerability disclosure programs, both public, both with explicit safe-harbour authorisation, and neither discoverable by machine. The departmental VDP is operated on Bugcrowd; the FAA runs its own separate program by email. Automated discovery fails completely: no host in the department publishes an RFC 9116 /.well-known/security.txt (every probe 404, and the departmental web tier 403s automated clients outright), so a scanner sees nothing while two fully staffed programs are running. programs: - name: U.S. DOT Vulnerability Disclosure Policy operator: U.S. Department of Transportation, Office of the Chief Information Officer policy_url: https://www.transportation.gov/vulnerability-disclosure-policy policy_url_alt: https://www.dot.gov/vulnerability-disclosure-policy submission_url: https://bugcrowd.com/engagements/usdot-vdp platform: Bugcrowd contact: DOT-VDP@dot.gov bounty: false bounty_note: >- "DOT does not provide payment for vulnerability submissions and, by submitting a vulnerability report, you acknowledge that you have no expectation of payment and that you expressly waive any future payment claims against the U.S. Government related to your submission. Additionally, DOT will not provide any type of recognition for disclosed vulnerabilities." (verbatim) safe_harbor: true safe_harbor_text: >- "If you make a good faith effort to comply with this policy during your security research, we will consider your research to be authorized. We will work with you to understand and resolve the issue quickly, and DOT will not recommend or pursue legal action related to your research. Should legal action be initiated by a third party against you for activities that were conducted in accordance with this policy, we will make this authorization known." (verbatim) coordination: Cybersecurity and Infrastructure Security Agency (CISA) scope_domains: - 911.gov - bts.gov - cmts.gov - distracteddriving.gov - distraction.gov - dot.gov - ems.gov - flyhealthy.gov - nhtsa.gov - nhtsa.dot.gov - protectyourmove.gov - safecar.gov - safercar.gov - safertruck.gov - safeocs.gov - trafficsafetymarketing.gov - transportation.gov - usmma.edu scope_note: >- Subdomains included. Explicitly excluded: FAA-operated sites (they carry their own VDP link), and any site DOT does not directly manage. "Any services not explicitly identified here are considered out-of-scope and are not authorized for testing." relevance_to_apis: >- data.transportation.gov, datahub.transportation.gov and data.bts.gov fall inside transportation.gov / bts.gov and are therefore in scope. The FAA API gateway hosts (external-api.faa.gov, external.apic4e.faa.gov, api.faa.gov) are NOT — they belong to the FAA program below. - name: FAA Vulnerability Disclosure Policy operator: Federal Aviation Administration policy_url: https://www.faa.gov/web_policies/vulnerability_disclosure_policy policy_date: '2023-01-26' submission_url: null platform: email contact: vulnerabilitydisclosure@faa.gov bounty: false bounty_note: >- "the FAA does not provide payment for vulnerability submissions ... Additionally the FAA will not provide any type of recognition for disclosed vulnerabilities." (verbatim) safe_harbor: true safe_harbor_text: >- "If you make a good faith effort to comply with this policy during your security research, the FAA will consider your research to be authorized, work with you to understand and resolve the issue quickly, and will not recommend or pursue legal action related to your research conducted pursuant to this policy." (verbatim) disclosure_embargo_days: 90 disclosure_embargo_text: >- "The FAA requires that reporters of vulnerabilities refrain from public disclosure for a minimum of 90 calendar days from the date the FAA acknowledges receipt of the report." acknowledgement_sla: 3 business days when contact information is shared anonymous_reports_accepted: true coordination: [CISA, Transportation Security Administration (TSA), affected vendors and open source projects] scope_note: >- "This policy applies to all public-facing FAA systems and services." That covers every FAA API host in this repo — external-api.faa.gov, external.apic4e.faa.gov, api.faa.gov, catalog.data.faa.gov. Researchers unsure whether a system is in scope are told to email vulnerabilitydisclosure@faa.gov before starting. prohibited_methods: - Testing systems outside the declared scope - Physical testing of facilities - Social engineering / phishing of FAA users - Denial of Service or Resource Exhaustion attacks - Introducing malicious software - Testing third-party applications that integrate with FAA systems - Deleting, altering, sharing, retaining or destroying FAA data - Exfiltrating data, establishing command line access or persistence, or pivoting security_txt: published: false probes: - {host: external-api.faa.gov, path: /.well-known/security.txt, status: 404} - {host: external.apic4e.faa.gov, path: /.well-known/security.txt, status: 404} - {host: www.faa.gov, path: /.well-known/security.txt, status: 404} - {host: catalog.data.faa.gov, path: /.well-known/security.txt, status: 404} - {host: data.transportation.gov, path: /.well-known/security.txt, status: 404} - {host: datahub.transportation.gov, path: /.well-known/security.txt, status: 404} - {host: data.bts.gov, path: /.well-known/security.txt, status: 404} - {host: www.transportation.gov, path: /.well-known/security.txt, status: 403, note: Akamai bot block; cannot be confirmed either way} - {host: www.bts.gov, path: /.well-known/security.txt, status: 403, note: Akamai bot block} - {host: api.faa.gov, path: /.well-known/security.txt, status: 200, note: FALSE POSITIVE — Gravitee portal serves its Angular index.html for every unmatched path} finding: >- Both programs would be trivially machine-discoverable with a nine-line security.txt on each host. Neither publishes one. This is the single cheapest fix available to the department. evidence: - source: https://www.faa.gov/web_policies/vulnerability_disclosure_policy kind: disclosure-policy-page status: 200 verified: '2026-07-28' note: Fetched with a browser User-Agent; the FAA web tier serves automated clients normally. - source: https://bugcrowd.com/engagements/usdot-vdp kind: bug-bounty-platform-engagement status: 200 verified: '2026-07-28' - source: https://www.transportation.gov/vulnerability-disclosure-policy kind: disclosure-policy-page status: 403 verified: '2026-07-28' note: >- Live host returns Akamai "Access Denied" to every non-browser client including a spoofed Chrome User-Agent. Content read from the Internet Archive capture web.archive.org/web/20260727163352/ and cross-checked against the search index.