Federal Mine Safety And Health Review Commission Vulnerability Disclosure
FMSHRC publishes a Vulnerability Disclosure Policy dated January 2024, in the form required of federal civilian agencies by CISA Binding Operational Directive 20-01. The policy is linked from the site footer as an HTML landing page whose body is a single link to a Section 508-remediated PDF; the substance lives in the PDF. It grants safe harbor for good-faith research, names an in-scope system, states acknowledgement timelines, and accepts anonymous reports. It was NOT discoverable by machine: no /.well-known/security.txt is served on any FMSHRC host (all 404), so the automated security-programs probe found nothing and this was located by reading the site navigation. Publishing an RFC 9116 security.txt pointing at this same policy would make it machine-findable at no cost.
Federal Mine Safety and Health Review Commission runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.