National Council on Disability · Vulnerability Disclosure
National Council On Disability Vulnerability Disclosure
Vulnerability disclosure
National Council on Disability runs a coordinated vulnerability disclosure program on Hackerone.
DisabilityFederal GovernmentPolicyCivil RightsHealthcareIndependent Agency
Program: Hackerone
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
generated: '2026-09-14'
method: searched
source: https://www.ncd.gov/accountability/vulnerability-disclosure-policy/
provider: National Council on Disability
providerId: national-council-on-disability
program:
published: true
name: NCD Vulnerability Disclosure Policy
url: https://www.ncd.gov/accountability/vulnerability-disclosure-policy/
pdf: https://www.ncd.gov/assets/uploads/docs/national-council-on-disability-vulnerability-disclosure-policy-21-0601.pdf
version: '1.0'
issued: '2021-06-01'
change_history:
- version: '1.0'
date: '2021-06-01'
description: First issuance
driver: >-
CISA Binding Operational Directive 20-01, which directs US federal executive-branch
agencies to publish a vulnerability disclosure policy.
safe_harbor:
offered: true
statement: >-
"If you make a good faith effort to comply with this policy during your security
research, we will consider your research to be authorized and we will work with you to
understand and resolve the issue quickly, and NCD will not recommend or pursue legal
action related to your research."
third_party_support: >-
NCD states it will make the authorization known if a third party initiates legal action
over research conducted under this policy.
scope:
in_scope:
- NCD.GOV
- NCD systems or services
out_of_scope:
- Any connected service not expressly listed
- Vulnerabilities in vendor systems (report to the vendor directly)
prohibited_methods:
- Network denial of service (DoS/DDoS) or any test that impairs access or damages a system or data
- Physical testing (office access, open doors, tailgating)
- Social engineering (phishing, vishing) or other non-technical vulnerability testing
reporting:
channel: email
address: security@agency.gov
anonymous_accepted: true
pgp_supported: false
sensitive_submission_url: https://ncd.gov/about
acknowledgement_sla: 3 business days
escalation: >-
Reports affecting all users of a product or service (not solely NCD) may be shared with
CISA and handled under its coordinated vulnerability disclosure process. NCD states it
will not share reporter name or contact information without express permission.
disclosure:
researcher_embargo_days: 90
vendor_notification_schedule:
- Initial attempt when the vulnerability is identified
- Second attempt no less than one week after the initial attempt
- Third attempt no less than two weeks after the initial attempt
cert_escalation_days: 45
cert_bodies:
- CERT/CC
- ICS-CERT
- national CERT
bug_bounty:
offered: false
note: No monetary bounty, platform (HackerOne/Bugcrowd/Intigriti) or hall of fame is offered.
security_txt:
published: false
probed:
- url: https://www.ncd.gov/.well-known/security.txt
status: 404
- url: https://ncd.gov/.well-known/security.txt
status: 404
findings:
- severity: defect
finding: >-
The reporting address published in the policy is "security@agency.gov" — the literal
placeholder from the CISA BOD 20-01 / vulnerability-disclosure-policy-template, never
replaced with an ncd.gov mailbox. A researcher following the policy as written would
mail a domain NCD does not control. Verified in both the HTML page and the linked PDF
text as the only email address the document contains.
evidence: https://www.ncd.gov/accountability/vulnerability-disclosure-policy/
- severity: gap
finding: >-
No /.well-known/security.txt (RFC 9116) on either host, so the policy is discoverable
only by browsing the Accountability section — automated scanners and agents will not
find it. The policy also sits at /accountability/vulnerability-disclosure-policy/ rather
than the /vulnerability-disclosure-policy path BOD 20-01 names (that path 404s).
evidence: https://www.ncd.gov/vulnerability-disclosure-policy/
- severity: gap
finding: >-
The sensitive-submission fallback points at https://ncd.gov/about, which serves a
client-side meta-refresh redirect page rather than a submission form.
evidence: https://ncd.gov/about
maintainers:
- FN: Kin Lane
email: kin@apievangelist.com
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/national-council-on-disability-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.