Commission of Fine Arts · Vulnerability Disclosure

Commission Of Fine Arts Vulnerability Disclosure

Vulnerability disclosure

Commission of Fine Arts publishes a vulnerability disclosure policy for reporting security issues. A dedicated security contact is published.

ArchitectureArtsDesign ReviewFederal-GovernmentWashington DC
Program:

Disclosure Policy

Policy

Security Contact

Contact
security@cfa.gov
Contact
webmaster@cfa.gov

Source

Vulnerability Disclosure

commission-of-fine-arts-vulnerability-disclosure.yml Raw ↑
generated: '2026-09-05'
method: searched
probe: true
source: https://www.cfa.gov/vulnerability-disclosure-policy
note: >-
  The CFA publishes a full CISA-aligned agency Vulnerability Disclosure Policy
  at a non-standard path (/vulnerability-disclosure-policy), which is why the
  mechanical probe-security-programs.py sweep — which checks
  /vulnerability-disclosure, /responsible-disclosure, /security and
  /.well-known/security.txt — recorded vdp=none. Found by walking the agency
  sitemap.xml. No /.well-known/security.txt is served (404), so the policy is
  human-discoverable only.
policy:
  - https://www.cfa.gov/vulnerability-disclosure-policy
contact:
  - security@cfa.gov
  - webmaster@cfa.gov
safe_harbor: true
anonymous_reports_accepted: true
bug_bounty: false
bounty_note: >-
  "you acknowledge that you have no expectation of payment and that you
  expressly waive any future pay claims against the U.S. Government" — quoted
  from the policy.
coordination:
  body: Cybersecurity and Infrastructure Security Agency (CISA)
  note: >-
    Findings affecting all users of a product, not solely the CFA, may be shared
    with CISA and handled under their coordinated vulnerability disclosure
    process.
response_targets:
  - {milestone: acknowledgement, within: 3 business days}
  - {milestone: initial assessment and validity confirmation, within: 7 business days}
  - {milestone: reporter notified of resolution outcome, within: 90 days}
out_of_scope:
  - physical testing (office access, open doors, tailgating)
  - social engineering (phishing, vishing)
  - non-technical vulnerability testing
  - third-party vendor systems (report to the vendor)
evidence:
  - source: https://www.cfa.gov/vulnerability-disclosure-policy
    kind: agency vulnerability disclosure policy page
    http_status: 200
    fetched: '2026-09-05'
  - source: https://www.cfa.gov/website-policies
    kind: policy hub linking the VDP
    http_status: 200
    fetched: '2026-09-05'
  - source: https://www.cfa.gov/.well-known/security.txt
    kind: RFC 9116 probe
    http_status: 404
    fetched: '2026-09-05'

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/commission-of-fine-arts-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.