{"id":"7dce9446-f985-4317-a4a2-c0000f8cd102","engagementId":"38da405c-3e09-40a6-bff1-3059b64ae16b","data":{"brief":{"id":"de293c4f-8c4a-47e0-979d-92d99fa8e9b2","name":"U.S. Securities and Exchange Commission (SEC) - Vulnerability Disclosure Program","tagline":"The federal securities laws empower the Securities and Exchange Commission with broad authority over all aspects of the securities industry. The SEC’s mission is to protect investors; maintain fair, orderly, and efficient markets; and facilitate capital formation.","description":"\u003ch2\u003eIntroduction\u003c/h2\u003e\n\n\u003cp\u003eThe U.S. Securities and Exchange Commission (“SEC”) is committed to maintaining the security of its systems and protecting sensitive information from unauthorized disclosure. \u003c/p\u003e\n\n\u003cp\u003eThis policy is intended to give security researchers clear guidelines for conducting vulnerability discovery activities and to convey our preferences in how to submit discovered vulnerabilities to the SEC.  \u003c/p\u003e\n\n\u003cp\u003eThis policy describes what systems and types of research are covered under this policy, how to send the SEC vulnerability reports, and how long we ask security researchers to wait before publicly disclosing vulnerabilities. \u003c/p\u003e\n\n\u003cp\u003eWe encourage you to submit on this engagement to report potential vulnerabilities in our systems. \u003c/p\u003e","industryTagId":"9567dde1-261a-4b2f-9cb4-50b407d6c3d7","targetsOverview":"\u003ch2\u003eAuthorization\u003c/h2\u003e\n\n\u003cp\u003eIf you make a good faith effort to comply with this policy during your security research, we will consider your research to be authorized, and we will work with you to understand and resolve the issue quickly. In addition, the SEC will not recommend or pursue legal action related to your research. Should legal action be initiated by a third party against you for research conducted in accordance with this policy, we will make this authorization known. \u003c/p\u003e\n\n\u003ch2\u003eGuidelines\u003c/h2\u003e\n\n\u003cp\u003eUnder this policy, “research” means activities in which you:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eNotify the SEC as soon as possible after you discover a real or potential security issue.\u003c/li\u003e\n\u003cli\u003eMake every effort to avoid privacy violations, degradation of user experience, disruption to production systems, and destruction or manipulation of data.\u003c/li\u003e\n\u003cli\u003eOnly use exploits to the extent necessary to confirm a vulnerability’s presence. Do not use an exploit to compromise or exfiltrate data, establish persistent command line access, or use the exploit to pivot to other systems.\u003c/li\u003e\n\u003cli\u003eProvide the SEC a reasonable amount of time to resolve the issue before you disclose it publicly.\u003c/li\u003e\n\u003cli\u003eDo not submit a high volume of low-quality reports.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eOnce you’ve established that a vulnerability exists or encounter any sensitive data (including personally identifiable information, financial information, or proprietary information or trade secrets of any party), you must stop your test, notify the SEC immediately, purge any stored SEC nonpublic data, and not disclose this data to anyone else.\u003c/p\u003e\n\n\u003ch2\u003eTest Methods\u003c/h2\u003e\n\n\u003cp\u003eThe following test methods are not authorized:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eTesting any system other than the systems set forth in the “Scope” section below;\u003c/li\u003e\n\u003cli\u003eDisclosing vulnerability information except as set forth in the “Reporting a Vulnerability” section below;\u003c/li\u003e\n\u003cli\u003eNetwork denial of service (DoS or DDoS) tests or other tests that impair access to or damage a system or data such as resource exhaustion attacks;\u003c/li\u003e\n\u003cli\u003ePhysical testing of facilities or resources (e.g., office access, open doors, tailgating);\u003c/li\u003e\n\u003cli\u003eSocial engineering (e.g., phishing, vishing) or sending unsolicited electronic mail to SEC users, including “phishing” messages;\u003c/li\u003e\n\u003cli\u003eIntroducing malicious software;\u003c/li\u003e\n\u003cli\u003eTesting third-party applications, websites, or services that integrate with or link to or from SEC systems;\u003c/li\u003e\n\u003cli\u003eDeleting, altering, sharing, retaining, or destroying SEC data, or rendering SEC data inaccessible; and\u003c/li\u003e\n\u003cli\u003eUsing an exploit to exfiltrate data, establish command line access, establish a persistent presence on SEC systems, or “pivot” to other SEC systems.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eScope\u003c/h2\u003e\n\n\u003cp\u003eThe SEC considers all internet-accessible systems or services in scope of our policy.\u003c/p\u003e\n\n\u003cp\u003eThe SEC asks that, for any SEC systems hosted by a cloud service or third-party provider, researchers follow the testing rules laid out by that service provider. These rules may be more restrictive than what is laid out in this policy. \u003c/p\u003e\n\n\u003cp\u003e\u003cem\u003eNote on Public SEC Data\u003c/em\u003e\u003cbr\u003e\n\u003ca href=\"https://www.sec.gov/Archives/edgar/data/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://www.sec.gov/Archives/edgar/data/\u003c/a\u003e and EDGAR search portals are intended for public distribution by design. Access to these documents does not constitute an information disclosure vulnerability and will be closed as out of scope.\u003c/p\u003e\n\n\u003ch2\u003eOut of Scope Systems\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eAny connected services to commercial entities or other government agencies are excluded from scope and are not authorized for testing.\u003c/li\u003e\n\u003cli\u003eAdditionally, vulnerabilities found in systems from our vendors fall outside of this policy’s scope and should be reported directly to the vendor according to their disclosure policy (if any).\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eIf you are not sure whether a system is in scope or not, contact the SEC at \u003ca href=\"mailto:vulnerabilitydisclosure@sec.gov\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003evulnerabilitydisclosure@sec.gov\u003c/a\u003e before starting your research (or at the security contact for the system’s domain name listed in the \u003ca href=\"https://domains.dotgov.gov/dotgov-web/registration/whois.xhtml\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003e.gov WHOIS\u003c/a\u003e, which is the public database that stores the information collected when someone registers a domain name).\u003c/p\u003e\n\n\u003ch2\u003eReporting a Vulnerability\u003c/h2\u003e\n\n\u003cp\u003eInformation submitted under this policy will be used for defensive purposes only – to mitigate or remediate vulnerabilities. If your findings include newly discovered vulnerabilities that affect all users of a product or service and not solely SEC, we may share your report with the Cybersecurity and Infrastructure Security Agency, where it will be handled under their \u003ca href=\"https://www.cisa.gov/coordinated-vulnerability-disclosure-process\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ecoordinated vulnerability disclosure process\u003c/a\u003e. We will not voluntarily share your name or contact information without your express permission.\u003c/p\u003e\n\n\u003cp\u003eWe accept vulnerability reports via this engagement. We may contact researchers to clarify reported vulnerability information or other technical information.\u003c/p\u003e\n\n\u003cp\u003eReports should provide a detailed technical description of the steps required to reproduce the vulnerability, including a description of any tools needed to identify or exploit the vulnerability. Images, e.g., screen captures, and other documents may be attached to reports. It is helpful to give attachments illustrative names. Reports may include proof-of-concept code that demonstrates exploitation of the vulnerability. We request that any scripts or exploit code be embedded into non-executable file types. We can process common file types and archive formats.\u003c/p\u003e\n\n\u003ch2\u003eWhat We Would Like to See from You\u003c/h2\u003e\n\n\u003cp\u003eTo help the SEC triage and prioritize submissions, we recommend that your reports:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eDescribe the location the vulnerability was discovered and the potential impact of exploitation;\u003c/li\u003e\n\u003cli\u003eOffer a detailed description of the steps needed to reproduce the vulnerability (proof of concept scripts or screenshots are helpful); and\u003c/li\u003e\n\u003cli\u003eBe in English, if possible.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eWhat You Can Expect from the SEC\u003c/h2\u003e\n\n\u003cp\u003eWhen you choose to share your contact information with the SEC, we commit to coordinating with you as openly and as quickly as possible.\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eWe will do our best to acknowledge that your report has been received within 3 business days of receipt.\u003c/li\u003e\n\u003cli\u003eTo the best of our ability, we will confirm the existence of the vulnerability to you and be as transparent as possible about what steps we are taking during the remediation process, including on issues or challenges that may delay resolution.\u003c/li\u003e\n\u003cli\u003eWe will maintain an open dialogue to the extent necessary to identify and mitigate confirmed vulnerabilities affecting an SEC information system.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eDisclosure\u003c/h2\u003e\n\n\u003cp\u003eThe SEC is committed to timely correction of vulnerabilities. However, we recognize that public disclosure of a vulnerability in absence of a readily-available corrective action likely increases versus decreases risk. Accordingly, we require that you refrain from sharing information about discovered vulnerabilities \u003cstrong\u003euntil given explicit permission to share the information\u003c/strong\u003e. If you believe others should be informed of the vulnerability prior to our implementation of corrective actions, we require that you coordinate in advance with us.\u003c/p\u003e\n\n\u003ch2\u003eQuestions\u003c/h2\u003e\n\n\u003cp\u003eQuestions regarding this policy may be sent to \u003ca href=\"mailto:vulnerabilitydisclosure@sec.gov\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003evulnerabilitydisclosure@sec.gov\u003c/a\u003e. The SEC encourages security researchers to contact the SEC for clarification on any element of this policy. Please contact the SEC prior to conducting research if you are unsure if a specific test method is inconsistent with or unaddressed by this policy. We also invite security researchers to contact the SEC with suggestions for improving this policy.\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"f7812e32-e995-4a48-8f09-f7d0cc8f5793","name":"In Scope Targets","targets":[{"id":"16d165c3-e2a8-4c76-8516-6add8bd9828b","uri":"https://www.sec.gov/","name":"*.sec.gov","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"8d5b9827-1580-4b3c-8bfd-a52ef93d30d2","sortOrder":0},"sortOrder":0,"tags":[{"id":"a5153b98-c545-4839-8a9a-f6e9f5cd2f29","name":"Website Testing","targetId":"16d165c3-e2a8-4c76-8516-6add8bd9828b"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"38da405c-3e09-40a6-bff1-3059b64ae16b","code":"sec-vdp","state":"in_progress","endsAt":null,"bountyId":"d7faa8cb-7a06-48b5-84f2-15397793e1fd","startsAt":"2026-08-11T18:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Government","methodologyName":null,"logoUrl":"https://bc-shard-mod-static.s3-fips.us-gov-west-1.amazonaws.com/logos/9681/e401/d04762f5/f282f5f41565e14128aab6b618b392ff_SEC_Logo.png?X-Amz-Algorithm=AWS4-HMAC-SHA256\u0026X-Amz-Credential=ASIAVVMNQJRCRVFGXRA7%2F20261005%2Fus-gov-west-1%2Fs3%2Faws4_request\u0026X-Amz-Date=20261005T014030Z\u0026X-Amz-Expires=900\u0026X-Amz-Security-Token=IQoJb3JpZ2luX2VjEOP%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaDXVzLWdvdi13ZXN0LTEiRjBEAiBdmcW%2FLv6z%2FkzsZVcLnrpUJxEiEvTIEgomh4jfwONkhAIgcHEOiHkLuzc%2FfRe%2BpvdlJhJD5QqEuZorQt6PFeSY2EUq9AMIEBAAGgwzODk1MjgxNzc3MzMiDCXHjb3%2Bq4bhx0AI8CrRA6ZX503lbVhGELOAmMb%2B2Lpx4jq3D4RVaZI%2Fb0j%2FT46plbnWqg47SvdLtkj4o5wH9xDMU0cJrKcD%2BDeYhvWzqDpAuo0xQirrXX0QewdVLbiVUFQlTnAnt0%2BXsQ5VnP%2FPS1hU7gDpdeop32obiWunUAGpl9EZpd86sDiqKfcOU%2FI%2FE46ag7PfDAtK9qnoqCxcgAf%2BVUyLC0SZCi0Zy4t%2BYJc0sHi48Y%2B7y1z4pspgbMQbueIKFMKIPvePlTGMwhmLwoMpznqhCJ%2B0Af5kEybqpERLmuUkdecBLgzI5PAG2IoOeBMwh02QrnFwbKgF1go8B5oodAHXTM9%2BJNT8t%2FLjkDs%2BQNgeO84KL%2BjqoxCH%2BiGk0fD9WwPYK1X16krUQPIDazJNzTWqoHnVozdxAOuvGtfu9j9eDqyDHrZ1gF9P6ikN4dS2UO5I4mPW0E5L%2Ff1IR9b6Snos33fyrLMGWbnTe%2Fk9E5r8waH%2F14V%2FOqgKr70YSlAZVqONetZhYyV6MxLgo0BDkZDLCHHSi1mhN8LzZFjxCXuIt5zLxVmRgzaGs5mklQHxMJJv9xS7UmKtmC%2BgQvwM7UGCyajVpxlP1KVPH%2FG04NaG2a%2BBJV0j0zaGm2YU%2FDCn94vWBjqmATY9McYV1vclin4h29AODdAPOQLZIBTgZADBTv2%2FsILK75qCzhM8EXTSWDXUfEBKsd8psqHK4Ajaehtq%2Bh6MdrZiEP8gVJMX3pmVljCK%2BrBFwbF7kkfRkZdh2zefPjdybWWT7RVH21DEoOb%2B4G8VhJIy46Zeh4ofAVN9c%2Bt%2FGUWpiuBFRwjwEw8Y%2BeDU845Rc6pUupiL9veHS7%2BA4YftMxQwuIBux0k%3D\u0026X-Amz-SignedHeaders=host\u0026X-Amz-Signature=3c69d8e087cd9c7b648a3306865de7ac1aecad60dbb3199a4e26ddf8a0668629","logoBackgroundColor":"#ffffff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"no_reward","engagementTypeDetail":{"iconVariant":"vdp","productLabel":"Vulnerability Disclosure","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2026-08-11T18:00:00.471Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/sec-vdp","changelogs":"/engagements/sec-vdp/changelog","submissions":null,"announcements":"/engagements/sec-vdp/announcements","hallOfFame":"/engagements/sec-vdp/hall_of_fames","crowdstream":"/engagements/sec-vdp/crowdstream"},"announcementsCount":0,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Priority Triage","submitReportUrl":"/engagements/sec-vdp/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=sec-vdp\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/sec-vdp/engagement_subscribers","engagementChangelogsUrl":"/engagements/sec-vdp/changelog","publishedAt":"2026-08-12T17:13:45.023Z","engagementChangelogUrl":"/engagements/sec-vdp/changelog/7dce9446-f985-4317-a4a2-c0000f8cd102","createUserFeedbacksUrl":"/engagements/sec-vdp/feedbacks","engagementCrowdstreamUrl":"/engagements/sec-vdp/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":"/auth/api/v1/users/me"}