Chief Human Capital Officers Council · Vulnerability Disclosure

Chief Human Capital Officers Vulnerability Disclosure

Vulnerability disclosure

Chief Human Capital Officers Council runs a coordinated vulnerability disclosure program on Bugcrowd.

CHCOFederal-GovernmentHR PolicyHuman CapitalHuman ResourcesInteragency CouncilOPMPublic SectorTalent AcquisitionWorkforce Management
Program: Bugcrowd

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

chief-human-capital-officers-vulnerability-disclosure.yml Raw ↑
generated: '2026-09-05'
method: searched
source: https://www.opm.gov/vulnerability-disclosure-policy/
provider: Chief Human Capital Officers Council
providerId: chief-human-capital-officers
ownership_note: >-
  This policy is published by the U.S. Office of Personnel Management, the agency that
  chairs the CHCO Council and hosts its entire web presence. It is recorded here because
  the policy's own Scope section names BOTH chcoc.gov and opm.gov explicitly — the two
  domains that serve this record — so it is the vulnerability disclosure program that
  actually governs the Council's public surface, not a neighbouring agency's policy
  borrowed by association.
program:
  name: OPM Vulnerability Disclosure Policy
  url: https://www.opm.gov/vulnerability-disclosure-policy/
  status: active
  type: vulnerability-disclosure-policy
  bounty: false
  bounty_note: OPM states it does not offer compensation for identifying or reporting vulnerabilities.
  platform: Bugcrowd
  platform_url: https://bugcrowd.com/opm-vdp
  authority: CISA Binding Operational Directive 20-01 (federal agency VDP requirement)
contacts:
  - type: email
    value: opm-vdp@submit.bugcrowd.com
    purpose: Submit a vulnerability report
  - type: web
    value: https://bugcrowd.com/opm-vdp
    purpose: Submit a vulnerability report
  - type: email
    value: vulnerabilitydisclosure@opm.gov
    purpose: Ask whether a system or endpoint is in scope before testing
scope:
  in_scope:
    - External-facing OPM registered and managed .gov domains and all sub-domains
    - chcoc.gov
    - opm.gov
    - applicationmanager.gov
    - cybercareers.gov
    - employeeexpress.gov
    - feb.gov
    - federaljobs.gov
    - fedjobs.gov
    - fedshirevets.gov
    - fsafeds.gov
    - golearn.gov
    - governmentjobs.gov
    - pac.gov
    - pmf.gov
    - telework.gov
    - unlocktalent.gov
    - usajobs.gov
    - usalearning.gov
    - usastaffing.gov
  out_of_scope:
    - Testing of third-party services OPM uses (non-public data published on them is in scope; testing them is not)
    - Any service not expressly listed in the policy, including connected services
    - Vulnerabilities in non-federal vendor systems (report to the vendor)
safe_harbor:
  present: true
  statement: >-
    OPM will consider good-faith research conducted within this policy to be authorized and
    will not pursue legal action against authorized research.
timelines:
  acknowledgement: Within 5 business days, when contact information is provided
  initial_response: Within 3 business days
  disclosure_embargo: Researchers keep findings confidential for up to 90 calendar days after notifying OPM
rules_of_engagement:
  prohibited:
    - Denial of service / resource exhaustion testing
    - Physical testing of federal or contractor facilities
    - Social engineering, phishing, vishing, unsolicited email
    - Introducing malicious software or code
    - Testing that deletes, alters, shares, retains or destroys data
    - Exfiltrating data, establishing command-line access, privilege escalation, persistence, or pivoting
    - Testing third-party applications or services that integrate with agency systems
  required:
    - Cease testing and notify OPM immediately on discovering a vulnerability
    - Cease testing and notify OPM immediately on discovering exposed non-public data or PII
    - Purge any stored agency non-public data upon reporting
gaps:
  - >-
    OPM does not serve an RFC 9116 /.well-known/security.txt on opm.gov, chcoc.gov or
    www.opm.gov — the policy is a web page only, so an automated agent cannot discover it.
    Probed 2026-09-05: https://www.opm.gov/.well-known/security.txt returned 503 with an
    HTML error body; https://www.chcoc.gov/.well-known/security.txt returned 301 to
    https://www.opm.gov/chcoc.
evidence:
  - url: https://www.opm.gov/vulnerability-disclosure-policy/
    http_status: 200
    fetched: '2026-09-05'
    note: Scope section names chcoc.gov and opm.gov verbatim
  - url: https://www.opm.gov/.well-known/security.txt
    http_status: 503
    fetched: '2026-09-05'
    note: HTML "Unexpected Error" page, not a security.txt
maintainers:
  - FN: Kin Lane
    email: kin@apievangelist.com

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/chief-human-capital-officers-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.