OpenSSF Scorecard
Security Policy and VDP

OpenSSF Scorecard OSSFSC-4: Security Policy, Vulnerability Disclosure, Responsible Reporting

Maintain security policy + vulnerability disclosure programme per OpenSSF Scorecard check Security-Policy + broader VDP best practice. Security Policy Published must (a) publish SECURITY.md file documenting reporting channel + scope + acknowledgment timeline + response process + (b) integrate with PSIRT or equivalent triage capability + (c) align with broader vulnerability disclosure programme + (d) honor responsible disclosure conventions. Vulnerability disclosure programme must (a) provide secure reporting channel (security@ email + Bugcrowd + HackerOne + similar) + (b) acknowledge reports within documented timeframe (typically 1-3 business days) + (c) triage + scope + remediate + coordinate disclosure + (d) recognize researcher contribution where appropriate. Integrate with broader product security operations + bug bounty + threat intelligence + customer communication.

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.