Bureau of International Labor Affairs · Vulnerability Disclosure

Bureau Of International Labor Affairs Vulnerability Disclosure

Vulnerability disclosure

Bureau of International Labor Affairs runs a coordinated vulnerability disclosure program on Bugcrowd. A dedicated security contact is published.

Federal-GovernmentInternationalLaborStandardsChild LaborForced LaborHuman Trafficking
Program: Bugcrowd

Disclosure Policy

Security Contact

Contact
notePublished on the policy page as "m-DOLCSIRC[at]dol[dot]gov" for scope clarification.
Contact
scope_questionsm-DOLCSIRC@dol.gov

Source

Vulnerability Disclosure

bureau-of-international-labor-affairs-vulnerability-disclosure.yml Raw ↑
generated: '2026-09-05'
method: searched
source: https://www.dol.gov/vulnerability-disclosure-policy
provider: Bureau of International Labor Affairs
providerId: bureau-of-international-labor-affairs
summary: >-
  The U.S. Department of Labor publishes a vulnerability disclosure policy covering
  *.dol.gov, which includes every host ILAB's data is served from. Reports are taken
  through a public Bugcrowd program. There is no RFC 9116 /.well-known/security.txt.
published: true
policy_url: https://www.dol.gov/vulnerability-disclosure-policy
policy_status: 200
policy_note: >-
  Returns 403 to a plain crawler User-Agent because of the dol.gov Akamai bot policy;
  fetched successfully with a browser-class client on 2026-09-05. The page exists and
  is public.
program:
  platform: Bugcrowd
  url: https://bugcrowd.com/dol-vdp
  status: 200
  type: vulnerability-disclosure-program
  bounty: false
  note: >-
    A VDP, not a paid bug bounty. Verified reachable 2026-09-05.
contact:
  scope_questions: m-DOLCSIRC@dol.gov
  note: >-
    Published on the policy page as "m-DOLCSIRC[at]dol[dot]gov" for scope clarification.
scope:
  in_scope:
    - '*.dol.gov'
    - '*.bls.gov'
    - '*.osha.gov'
    - '*.msha.gov'
  note: >-
    The policy enumerates dozens of DOL-related domains. apiprod.dol.gov,
    dataportal.dol.gov, data.dol.gov and www.dol.gov all fall under *.dol.gov.
  out_of_scope: >-
    "Any service not expressly listed above, such as any connected services, are excluded
    from scope."
basis: >-
  CISA Binding Operational Directive 20-01, which requires every U.S. federal civilian
  executive branch agency to publish a vulnerability disclosure policy.
security_txt:
  published: false
  probed:
    - url: https://www.dol.gov/.well-known/security.txt
      status: 403
      note: Akamai edge denial, not a served document.
    - url: https://apiprod.dol.gov/.well-known/security.txt
      status: 403
      note: AWS API Gateway route-not-found.
    - url: https://dataportal.dol.gov/.well-known/security.txt
      status: 200
      note: SPA catch-all HTML shell, not a document.
  detail: >-
    No RFC 9116 security.txt is served on any host. The policy is HTML-only, so an agent
    cannot discover it mechanically.
maintainers:
  - FN: Kin Lane
    email: kin@apievangelist.com

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/bureau-of-international-labor-affairs-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.