generated: '2026-09-04' method: searched probe: true source: https://www.vice.com/en/vice-responsible-disclosure-policy/ policy: - https://www.vice.com/en/vice-responsible-disclosure-policy/ contact: - infosec@vice.com pgp: true safe_harbor: true bug_bounty: false bug_bounty_platform: null security_txt: false note: VICE publishes a real, substantive responsible-disclosure policy with a named security contact, PGP availability and explicit safe-harbor language - 'We won't take legal action against or suspend or terminate your account access provided you discover and report security vulnerabilities in accordance with this Responsible Disclosure Policy.' It states plainly that 'Vice Media does not compensate individuals or organizations for identifying potential or confirmed vulnerabilities', so there is no bounty and no HackerOne/Bugcrowd/Intigriti program. The policy is linked from the footer of every page but is NOT discoverable at /.well-known/security.txt, which returns HTTP 404 - the single cheapest fix available to this provider. scope_note: The policy prohibits testing third-party integrated services, accessing data not your own, denial of service, spam and malware, and excludes minors and sanctioned persons. commitments: - prompt acknowledgement - remediation timeline - notification on fix - public recognition on request evidence: - source: https://www.vice.com/en/vice-responsible-disclosure-policy/ status: 200 kind: disclosure-policy how_found: linked from the footer of https://www.vice.com/ (HTTP 200, fetched 2026-09-04) - source: https://www.vice.com/.well-known/security.txt status: 404 kind: security.txt