AmeriCorps · Vulnerability Disclosure
Americorps Vulnerability Disclosure
Vulnerability disclosure
AmeriCorps publishes a vulnerability disclosure policy for reporting security issues. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.
Federal-GovernmentNational ServiceVolunteerismCommunity DevelopmentCivic EngagementEducationDisaster ResponseEnvironmental Conservation
Program:
security.txt present
Disclosure Policy
Security Contact
Contact
{"channel" => "email", "detail" => "AmeriCorps OIT Help Desk — the address the policy names for vulnerability reports.", "value" => "oithd@cns.gov"}
Contact
{"channel" => "phone", "detail" => "AmeriCorps OIT Help Desk.", "value" => "+1-202-606-6600"}
Contact
{"channel" => "web form", "detail" => "Form linked from the policy page as a third reporting route.", "value" => "Privacy and Security Incident Report"}
Contact
{"channel" => "email", "detail" => "The registered .gov WHOIS security contact for every AmeriCorps domain, named on the policy page itself. This is the address that would appear in a security.txt if one were published.", "value" => "Unsafe@cns.gov"}
Source
Vulnerability Disclosure
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.