Federal Student Aid · Vulnerability Disclosure

Federal Student Aid Vulnerability Disclosure

Vulnerability disclosure

Federal Student Aid is an office of the U.S. Department of Education and is covered by the Department's published Vulnerability Disclosure Policy, issued under CISA Binding Operational Directive 20-01. The policy's scope is written system-wide rather than domain-by-domain, so StudentAid.gov, FSA Partner Connect and the College Scorecard docs host all fall inside it without being named.

Federal Student Aid runs a coordinated vulnerability disclosure program on Hackerone.

EducationFederal GovernmentFinancial AidGrantsLoansStudent Aid
Program: Hackerone

Disclosure Policy

Policy
Policy
Policy
Policy
Policy

Security Contact

Source

Vulnerability Disclosure

federal-student-aid-vulnerability-disclosure.yml Raw ↑
specification: API Commons VulnerabilityDisclosure
specificationVersion: '0.1'
provider: Federal Student Aid
providerId: federal-student-aid
generated: '2026-09-09'
method: searched
source: https://www.ed.gov/about/ed-overview/required-notices/vulnerability-disclosure-policy
modified: '2026-09-09'
description: >-
  Federal Student Aid is an office of the U.S. Department of Education and is
  covered by the Department's published Vulnerability Disclosure Policy, issued
  under CISA Binding Operational Directive 20-01. The policy's scope is written
  system-wide rather than domain-by-domain, so StudentAid.gov, FSA Partner Connect
  and the College Scorecard docs host all fall inside it without being named.
published: true
program_type: coordinated-disclosure
bug_bounty: false
bug_bounty_note: >-
  No paid bounty. This is a federal coordinated-disclosure program with legal safe
  harbour, not a HackerOne/Bugcrowd/Intigriti engagement.
policy:
  url: https://www.ed.gov/about/ed-overview/required-notices/vulnerability-disclosure-policy
  status: 200
  probed: '2026-09-09'
  note: >-
    https://www.ed.gov/vulnerability-disclosure-policy 301-redirects here.
  authority: CISA Binding Operational Directive 20-01
scope:
  covered: >-
    "All internet-accessible, public facing, systems or services of the Department"
  excluded: Non-federal vendor systems.
  named_domains: []
  named_domains_note: >-
    The policy asserts coverage by class, not by hostname; no domain list is
    published, so inclusion of studentaid.gov is inferred from the class rather than
    stated.
reporting:
  portal: https://usdeptofed.responsibledisclosure.com/hc/en-us/requests/new
  email: OCIO_VDP@ed.gov
  email_purpose: questions about the policy
  anonymous_reports: true
safe_harbor:
  provided: true
  quote: >-
    "For those security research activities conducted in accordance with the
    restrictions and guidelines set forth in this policy... the Department will deem
    such activities authorized and (1) will not recommend or pursue legal action"
timelines:
  acknowledgement: 3 business days
  embargo: 90 calendar days
  embargo_quote: >-
    "the Department requests that security researchers refrain from sharing
    information about discovered vulnerabilities for ninety (90) calendar days after
    receiving an acknowledgement of receipt"
security_txt:
  published: false
  probed:
    - url: https://studentaid.gov/.well-known/security.txt
      status: 404
    - url: https://collegescorecard.ed.gov/.well-known/security.txt
      status: 404
    - url: https://fsapartners.ed.gov/.well-known/security.txt
      status: 404
    - url: https://api.data.gov/.well-known/security.txt
      status: 404
    - url: https://www.ed.gov/.well-known/security.txt
      status: 403
  note: >-
    The policy exists as an HTML page but is not advertised at any RFC 9116
    /.well-known/security.txt on any host this record knows. A researcher who looks
    where the standard says to look finds nothing — that is the actionable gap here,
    and it is cheap for the Department to close.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/federal-student-aid-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.