Federal Mine Safety And Health Review Commission Vulnerability Disclosure

Vulnerability disclosure

FMSHRC publishes a Vulnerability Disclosure Policy dated January 2024, in the form required of federal civilian agencies by CISA Binding Operational Directive 20-01. The policy is linked from the site footer as an HTML landing page whose body is a single link to a Section 508-remediated PDF; the substance lives in the PDF. It grants safe harbor for good-faith research, names an in-scope system, states acknowledgement timelines, and accepts anonymous reports. It was NOT discoverable by machine: no /.well-known/security.txt is served on any FMSHRC host (all 404), so the automated security-programs probe found nothing and this was located by reading the site navigation. Publishing an RFC 9116 security.txt pointing at this same policy would make it machine-findable at no cost.

Federal Mine Safety and Health Review Commission runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

Federal GovernmentMine SafetyAdjudicationOccupational SafetyLegalRegulatory-Enforcement
Program: Hackerone security.txt present

Disclosure Policy

Policy
Policy

Security Contact

Contact
mailto:ITSecurity@fmshrc.gov
Contact
https://bugcrowd.com/engagements/fcc-vdp

Source

Vulnerability Disclosure

federal-mine-safety-and-health-review-commission-vulnerability-disclosure.yml Raw ↑
generated: '2026-09-09'
method: searched
probe: true
source: https://www.fmshrc.gov/content/vulnerability-disclosure-policy
provider: Federal Mine Safety and Health Review Commission
providerId: federal-mine-safety-and-health-review-commission
description: >-
  FMSHRC publishes a Vulnerability Disclosure Policy dated January 2024, in the form
  required of federal civilian agencies by CISA Binding Operational Directive 20-01.
  The policy is linked from the site footer as an HTML landing page whose body is a
  single link to a Section 508-remediated PDF; the substance lives in the PDF. It grants
  safe harbor for good-faith research, names an in-scope system, states acknowledgement
  timelines, and accepts anonymous reports. It was NOT discoverable by machine: no
  /.well-known/security.txt is served on any FMSHRC host (all 404), so the automated
  security-programs probe found nothing and this was located by reading the site
  navigation. Publishing an RFC 9116 security.txt pointing at this same policy would make
  it machine-findable at no cost.
policy:
  - https://www.fmshrc.gov/content/vulnerability-disclosure-policy
  - https://www.fmshrc.gov/sites/default/files/Vulnerability%2520Disclosure%2520Policy_508.pdf
policy_dated: '2024-01'
contact:
  - mailto:ITSecurity@fmshrc.gov
  - https://bugcrowd.com/engagements/fcc-vdp
contact_note: >-
  The policy text reads: "We accept vulnerability reports through our bugcrowd program
  (https://bugcrowd.com/fcc-vdp) and questions can be directed to ITSecurity@fmshrc.gov."
  That Bugcrowd engagement slug is the FEDERAL COMMUNICATIONS COMMISSION's program
  (fcc-vdp), not an FMSHRC one — https://bugcrowd.com/fmshrc returns 404 while
  https://bugcrowd.com/fcc-vdp resolves 200 to https://bugcrowd.com/engagements/fcc-vdp.
  Recorded verbatim as published, flagged as an apparent copy error in the agency's own
  document. A researcher following the published link would file against a different
  agency. The email address is the reliable channel.
anonymous_reports_accepted: true
safe_harbor: true
safe_harbor_terms:
  - Good-faith research conducted under the policy is considered authorized; FMSHRC will not recommend or pursue legal action related to it.
  - If a third party initiates legal action for activity conducted in accordance with the policy, FMSHRC will make the authorization known.
sla:
  acknowledgement: within 3 business days when contact information is shared
  acknowledgement_alt: >-
    The policy states both "within 5 business days" (reporting section) and "within
    3 business days" (what-you-can-expect section); both figures are quoted as published.
in_scope:
  - fmshrc.gov
out_of_scope:
  - Any service not expressly listed, including connected services.
  - Vulnerabilities in vendor systems, which are to be reported to the vendor under the vendor's own disclosure policy.
prohibited_test_methods:
  - Network denial of service (DoS/DDoS) or any test that impairs access to or damages a system or data.
  - Physical testing (office access, open doors, tailgating).
  - Social engineering (phishing, vishing) or other non-technical vulnerability testing.
researcher_guidelines:
  - Notify FMSHRC as soon as possible after discovering a real or potential security issue.
  - Avoid privacy violations, degradation of user experience, disruption to production systems, and destruction or manipulation of data.
  - Use exploits only to the extent necessary to confirm a vulnerability's presence; do not exfiltrate data, establish persistent command-line access, or pivot to other systems.
  - Allow reasonable time to resolve the issue before public disclosure.
  - Do not submit a high volume of low-quality reports.
  - Stop testing and notify immediately on encountering sensitive data; do not disclose it to anyone else.
onward_sharing: >-
  Reports affecting all users of a product or service, not solely FMSHRC, may be shared
  with the Cybersecurity and Infrastructure Security Agency (CISA). Reporter name and
  contact information are not shared without express permission.
bug_bounty:
  published: false
  platforms_checked: [HackerOne, Bugcrowd, Intigriti]
  note: >-
    No FMSHRC bounty program exists. The Bugcrowd link in the policy points at the FCC's
    engagement; see contact_note. This is a disclosure program, not a paid bounty.
security_txt:
  served: false
  probed:
    - https://www.fmshrc.gov/.well-known/security.txt
    - https://fmshrc.gov/.well-known/security.txt
    - https://fmshrc-ecms.entellitrak.com/.well-known/security.txt
  status: 404
evidence:
  - url: https://www.fmshrc.gov/content/vulnerability-disclosure-policy
    status: 200
    kind: disclosure-policy landing page (live probe)
  - url: https://www.fmshrc.gov/sites/default/files/Vulnerability%2520Disclosure%2520Policy_508.pdf
    status: 200
    kind: disclosure policy PDF, application/pdf, 261889 bytes (live probe, text extracted)
  - url: https://bugcrowd.com/engagements/fcc-vdp
    status: 200
    kind: bounty platform page named in the policy (belongs to the FCC)
  - url: https://bugcrowd.com/fmshrc
    status: 404
    kind: control probe — no FMSHRC Bugcrowd engagement exists
  - url: https://www.fmshrc.gov/.well-known/security.txt
    status: 404
    kind: security.txt (live probe)
maintainers:
  - FN: Kin Lane
    email: kin@apievangelist.com

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/federal-mine-safety-and-health-review-commission-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.