Chief Human Capital Officers Council · Vulnerability Disclosure
Chief Human Capital Officers Vulnerability Disclosure
Vulnerability disclosure
Chief Human Capital Officers Council runs a coordinated vulnerability disclosure program on Bugcrowd.
CHCOFederal-GovernmentHR PolicyHuman CapitalHuman ResourcesInteragency CouncilOPMPublic SectorTalent AcquisitionWorkforce Management
Program: Bugcrowd
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
generated: '2026-09-05'
method: searched
source: https://www.opm.gov/vulnerability-disclosure-policy/
provider: Chief Human Capital Officers Council
providerId: chief-human-capital-officers
ownership_note: >-
This policy is published by the U.S. Office of Personnel Management, the agency that
chairs the CHCO Council and hosts its entire web presence. It is recorded here because
the policy's own Scope section names BOTH chcoc.gov and opm.gov explicitly — the two
domains that serve this record — so it is the vulnerability disclosure program that
actually governs the Council's public surface, not a neighbouring agency's policy
borrowed by association.
program:
name: OPM Vulnerability Disclosure Policy
url: https://www.opm.gov/vulnerability-disclosure-policy/
status: active
type: vulnerability-disclosure-policy
bounty: false
bounty_note: OPM states it does not offer compensation for identifying or reporting vulnerabilities.
platform: Bugcrowd
platform_url: https://bugcrowd.com/opm-vdp
authority: CISA Binding Operational Directive 20-01 (federal agency VDP requirement)
contacts:
- type: email
value: opm-vdp@submit.bugcrowd.com
purpose: Submit a vulnerability report
- type: web
value: https://bugcrowd.com/opm-vdp
purpose: Submit a vulnerability report
- type: email
value: vulnerabilitydisclosure@opm.gov
purpose: Ask whether a system or endpoint is in scope before testing
scope:
in_scope:
- External-facing OPM registered and managed .gov domains and all sub-domains
- chcoc.gov
- opm.gov
- applicationmanager.gov
- cybercareers.gov
- employeeexpress.gov
- feb.gov
- federaljobs.gov
- fedjobs.gov
- fedshirevets.gov
- fsafeds.gov
- golearn.gov
- governmentjobs.gov
- pac.gov
- pmf.gov
- telework.gov
- unlocktalent.gov
- usajobs.gov
- usalearning.gov
- usastaffing.gov
out_of_scope:
- Testing of third-party services OPM uses (non-public data published on them is in scope; testing them is not)
- Any service not expressly listed in the policy, including connected services
- Vulnerabilities in non-federal vendor systems (report to the vendor)
safe_harbor:
present: true
statement: >-
OPM will consider good-faith research conducted within this policy to be authorized and
will not pursue legal action against authorized research.
timelines:
acknowledgement: Within 5 business days, when contact information is provided
initial_response: Within 3 business days
disclosure_embargo: Researchers keep findings confidential for up to 90 calendar days after notifying OPM
rules_of_engagement:
prohibited:
- Denial of service / resource exhaustion testing
- Physical testing of federal or contractor facilities
- Social engineering, phishing, vishing, unsolicited email
- Introducing malicious software or code
- Testing that deletes, alters, shares, retains or destroys data
- Exfiltrating data, establishing command-line access, privilege escalation, persistence, or pivoting
- Testing third-party applications or services that integrate with agency systems
required:
- Cease testing and notify OPM immediately on discovering a vulnerability
- Cease testing and notify OPM immediately on discovering exposed non-public data or PII
- Purge any stored agency non-public data upon reporting
gaps:
- >-
OPM does not serve an RFC 9116 /.well-known/security.txt on opm.gov, chcoc.gov or
www.opm.gov — the policy is a web page only, so an automated agent cannot discover it.
Probed 2026-09-05: https://www.opm.gov/.well-known/security.txt returned 503 with an
HTML error body; https://www.chcoc.gov/.well-known/security.txt returned 301 to
https://www.opm.gov/chcoc.
evidence:
- url: https://www.opm.gov/vulnerability-disclosure-policy/
http_status: 200
fetched: '2026-09-05'
note: Scope section names chcoc.gov and opm.gov verbatim
- url: https://www.opm.gov/.well-known/security.txt
http_status: 503
fetched: '2026-09-05'
note: HTML "Unexpected Error" page, not a security.txt
maintainers:
- FN: Kin Lane
email: kin@apievangelist.com
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/chief-human-capital-officers-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.