Factiva · Vulnerability Disclosure

Factiva Vulnerability Disclosure

Vulnerability disclosure

Dow Jones — the publisher of Factiva — runs a published Vulnerability Disclosure Program, effective June 24, 2021, managed by Bugcrowd. There is no RFC 9116 security.txt served on any Factiva or Dow Jones host (see well-known/factiva-well-known.yml); the program is published as an HTML policy page linked from the site footer.

Factiva runs a coordinated vulnerability disclosure program on Bugcrowd. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

Artificial IntelligenceBusiness IntelligenceContent AggregationEnterprise DataGenAIMarket DataMedia MonitoringNewsNews APIResearchTaxonomy
Program: Bugcrowd security.txt present

Disclosure Policy

Policy
Policy

Security Contact

Contact
VDP@dowjones.com

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-13'
method: searched
probe: true
source: https://www.dowjones.com/security/
description: >-
  Dow Jones — the publisher of Factiva — runs a published Vulnerability Disclosure Program,
  effective June 24, 2021, managed by Bugcrowd. There is no RFC 9116 security.txt served on
  any Factiva or Dow Jones host (see well-known/factiva-well-known.yml); the program is
  published as an HTML policy page linked from the site footer.
program:
  name: Dow Jones Vulnerability Disclosure Program
  effective_date: '2021-06-24'
  managed_by: Bugcrowd
  type: vulnerability-disclosure
  bug_bounty: false
  bounty_note: >-
    The published policy describes coordinated disclosure managed through Bugcrowd; it does
    not advertise a paid bounty. Do not read this as a bounty program.
policy:
  - https://www.dowjones.com/security/
  - https://www.bugcrowd.com/resource/standard-disclosure-terms/
contact:
  - VDP@dowjones.com
submission:
  method: email
  address: VDP@dowjones.com
  instructions: >-
    Email VDP@dowjones.com including the information listed on Bugcrowd's "Report a Bug"
    page; Dow Jones forwards the report to Bugcrowd. Submissions are subject to Bugcrowd's
    Standard Disclosure Terms.
  reference: https://docs.bugcrowd.com/researchers/reporting-managing-submissions/reporting-a-bug/
disclosure_policy:
  public_notification: >-
    Dow Jones asks reporters not to post or share information about a potential vulnerability
    in a public setting until it has been researched, responded to and addressed.
security_txt: false
evidence:
  - source: https://www.dowjones.com/security/
    kind: disclosure-policy-page
    http_status: 200
    fetched: '2026-08-13'
    keywords:
      - vulnerability disclosure program
      - bugcrowd
      - VDP@dowjones.com
      - standard disclosure terms
  - source: https://www.dowjones.com/.well-known/security.txt
    kind: security.txt
    http_status: 404
    fetched: '2026-08-13'
    note: not served — soft-404 HTML shell.
maintainers:
  - FN: Kin Lane
    email: kin@apievangelist.com