National Council on Disability · Vulnerability Disclosure

National Council On Disability Vulnerability Disclosure

Vulnerability disclosure

National Council on Disability runs a coordinated vulnerability disclosure program on Hackerone.

DisabilityFederal GovernmentPolicyCivil RightsHealthcareIndependent Agency
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

national-council-on-disability-vulnerability-disclosure.yml Raw ↑
generated: '2026-09-14'
method: searched
source: https://www.ncd.gov/accountability/vulnerability-disclosure-policy/
provider: National Council on Disability
providerId: national-council-on-disability
program:
  published: true
  name: NCD Vulnerability Disclosure Policy
  url: https://www.ncd.gov/accountability/vulnerability-disclosure-policy/
  pdf: https://www.ncd.gov/assets/uploads/docs/national-council-on-disability-vulnerability-disclosure-policy-21-0601.pdf
  version: '1.0'
  issued: '2021-06-01'
  change_history:
    - version: '1.0'
      date: '2021-06-01'
      description: First issuance
  driver: >-
    CISA Binding Operational Directive 20-01, which directs US federal executive-branch
    agencies to publish a vulnerability disclosure policy.
safe_harbor:
  offered: true
  statement: >-
    "If you make a good faith effort to comply with this policy during your security
    research, we will consider your research to be authorized and we will work with you to
    understand and resolve the issue quickly, and NCD will not recommend or pursue legal
    action related to your research."
  third_party_support: >-
    NCD states it will make the authorization known if a third party initiates legal action
    over research conducted under this policy.
scope:
  in_scope:
    - NCD.GOV
    - NCD systems or services
  out_of_scope:
    - Any connected service not expressly listed
    - Vulnerabilities in vendor systems (report to the vendor directly)
  prohibited_methods:
    - Network denial of service (DoS/DDoS) or any test that impairs access or damages a system or data
    - Physical testing (office access, open doors, tailgating)
    - Social engineering (phishing, vishing) or other non-technical vulnerability testing
reporting:
  channel: email
  address: security@agency.gov
  anonymous_accepted: true
  pgp_supported: false
  sensitive_submission_url: https://ncd.gov/about
  acknowledgement_sla: 3 business days
  escalation: >-
    Reports affecting all users of a product or service (not solely NCD) may be shared with
    CISA and handled under its coordinated vulnerability disclosure process. NCD states it
    will not share reporter name or contact information without express permission.
disclosure:
  researcher_embargo_days: 90
  vendor_notification_schedule:
    - Initial attempt when the vulnerability is identified
    - Second attempt no less than one week after the initial attempt
    - Third attempt no less than two weeks after the initial attempt
  cert_escalation_days: 45
  cert_bodies:
    - CERT/CC
    - ICS-CERT
    - national CERT
bug_bounty:
  offered: false
  note: No monetary bounty, platform (HackerOne/Bugcrowd/Intigriti) or hall of fame is offered.
security_txt:
  published: false
  probed:
    - url: https://www.ncd.gov/.well-known/security.txt
      status: 404
    - url: https://ncd.gov/.well-known/security.txt
      status: 404
findings:
  - severity: defect
    finding: >-
      The reporting address published in the policy is "security@agency.gov" — the literal
      placeholder from the CISA BOD 20-01 / vulnerability-disclosure-policy-template, never
      replaced with an ncd.gov mailbox. A researcher following the policy as written would
      mail a domain NCD does not control. Verified in both the HTML page and the linked PDF
      text as the only email address the document contains.
    evidence: https://www.ncd.gov/accountability/vulnerability-disclosure-policy/
  - severity: gap
    finding: >-
      No /.well-known/security.txt (RFC 9116) on either host, so the policy is discoverable
      only by browsing the Accountability section — automated scanners and agents will not
      find it. The policy also sits at /accountability/vulnerability-disclosure-policy/ rather
      than the /vulnerability-disclosure-policy path BOD 20-01 names (that path 404s).
    evidence: https://www.ncd.gov/vulnerability-disclosure-policy/
  - severity: gap
    finding: >-
      The sensitive-submission fallback points at https://ncd.gov/about, which serves a
      client-side meta-refresh redirect page rather than a submission form.
    evidence: https://ncd.gov/about
maintainers:
  - FN: Kin Lane
    email: kin@apievangelist.com

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/national-council-on-disability-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.