Department of State · Vulnerability Disclosure
Department Of State Vulnerability Disclosure
Vulnerability disclosure
Department of State runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.
Federal-GovernmentForeign AffairsTravelConsularVisasPassports
Program: Hackerone
security.txt present
Disclosure Policy
Security Contact
Contact
vdpsubmission@state.gov
Source
Vulnerability Disclosure
generated: '2026-09-07'
method: searched
probe: true
source: https://www.state.gov/bureau-of-diplomatic-technology/vulnerability-disclosure-policy
summary: >-
The Department of State publishes a full Vulnerability Disclosure Policy issued by the Bureau of
Diplomatic Technology, with explicit safe-harbor authorization, a named scope, a coordinated
disclosure window and two intake channels including a HackerOne program. It is a genuine, current
disclosure program — it is simply not discoverable where a machine would look for it: there is no
/.well-known/security.txt on any State host, and the path 301s to an unrelated page (see
well-known/department-of-state-well-known.yml).
policy:
- https://www.state.gov/bureau-of-diplomatic-technology/vulnerability-disclosure-policy
contact:
- vdpsubmission@state.gov
bug_bounty:
platform: HackerOne
url: https://hackerone.com/us-department-of-state?type=team
paid: false
note: >-
Listed as a team page, used as the submission portal. The policy does not offer monetary awards;
it offers legal authorization for good-faith research.
submission_channels:
- kind: hackerone
url: https://hackerone.com/us-department-of-state?type=team
- kind: anonymous-web-form
url: https://hackerone.com/6b30fb0b-5a38-49c4-b23b-442da04cfb63/embedded_submissions/new
note: Embedded HackerOne form; the policy offers it for anonymous reporting.
- kind: email
target: vdpsubmission@state.gov
note: Also the address for scope questions and policy feedback.
scope:
in_scope: >-
"all Department internet accessible systems and services to include those specified at
HackerOne" — quoted verbatim from the policy.
out_of_scope: >-
Vendor systems. The policy directs those reports to the vendor's own disclosure policy.
escalation: >-
Researchers unsure whether a system is in scope are told to contact vdpsubmission@state.gov, or
the security contact for the domain in the .gov WHOIS at
https://domains.dotgov.gov/dotgov-web/registration/whois.xhtml, before starting.
safe_harbor: >-
"If you make a good faith effort to comply with this policy during your security research, we will
consider your research to be authorized and we will work with you to understand and resolve the
issue quickly, and Department of State will not recommend or pursue legal action related to your
research." The Department also commits to making that authorization known to a third party who
initiates action against a compliant researcher.
timelines:
acknowledgement: 3 business days when contact information is shared
coordinated_disclosure_window: typically 100 calendar days before public disclosure
prohibited_testing:
- Network denial or distributed denial of service (DoS/DDoS) and anything else that impairs access or damages data
- Physical testing (office access, open doors, tailgating)
- Social engineering (phishing, vishing) and other non-technical testing
- High volumes of low-quality reports
- Using an exploit beyond confirming presence — no exfiltration, no command-line access, no persistence, no pivoting
onward_sharing: >-
Reports affecting all users of a product may be shared with CISA and handled under its coordinated
vulnerability disclosure process (https://www.cisa.gov/coordinated-vulnerability-disclosure-process),
and with other U.S. Government entities where required by law. The Department commits not to share
a reporter's name or contact information without express permission.
history:
- version: '1.0'
date: '2021-03-04'
description: First issuance
- version: '1.1'
date: '2022-12-01'
description: Updated form for submitting a vulnerability report
regime:
directive: CISA Binding Operational Directive 20-01
note: >-
BOD 20-01 requires federal civilian agencies to publish a VDP and to serve it at
/.well-known/security.txt. The Department satisfies the policy half and not the discovery half.
evidence:
- source: https://www.state.gov/bureau-of-diplomatic-technology/vulnerability-disclosure-policy
kind: disclosure-policy-page
http_status: 200
fetched: '2026-09-07'
- source: https://hackerone.com/us-department-of-state?type=team
kind: bug-bounty-platform
http_status: 200
fetched: '2026-09-07'
- source: https://www.state.gov/.well-known/security.txt
kind: security.txt
http_status: 301
fetched: '2026-09-07'
note: Redirects to /state-gov-website-modernization/ — no RFC 9116 document is served.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/department-of-state-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.