A spiritual successor to Krebs's "how many Fortune 100 have a CISO?" — but for the thing that lets the outside world actually help: is there a verifiable way to report a bug, and how good is the policy? Every company below is graded against the disclose.io Maturity Model from its own published policy where one exists.
Snapshot 2026-06-20 · 100 companies · 22 graded directly from policy text · evidence + source on every row.
The maturity model is the yardstick — five rungs from "findable" to "accountable." The goal is a race to the top.
1 of the Fortune 100 reach Full Safe Harbor (L4+) — the ones that explicitly invite testing.
Click any row for the evidence quote, the source URL, and how it was graded. 29 companies differ between the submitted table and live verification (flagged ⚠ on the row); 6 of our independent grades differ from the public directory.
| # | Company | sec.txt | VDP / bounty | Our level | Dir. | vs dir | |
|---|---|---|---|---|---|---|---|
| 1 | Amazon amazon.com |
✓ | Contact | L1 | L2 | ±1 | ▸ |
|
Contact Only policy text · confidence high
“Contact: mailto:aws-security@amazon.com” “AWS Vulnerability Disclosure Program: https://hackerone.com/aws_vdp” “Policy: https://vdp.aws.security/” | |||||||
| 2 | Walmart walmart.com |
✓ | Bountydisc. | L2 | L2 | — | ▸ |
|
Basic VDP directory parse
No policy text graded — see provenance.
Source: directory: safeHarbor=None
| |||||||
| 3 | UnitedHealth Group unitedhealthgroup.com |
✓ | VDP | L2 | — | new | ▸ |
|
Basic VDP policy text · confidence high
“This policy prohibits the performance of the following activities: Hacking, penetration testing, or other attempts to gain unauthorized access to UnitedHealth Group software or systems; Active vulnerability scanning or testing;” “If you have discovered an issue that you believe is an in-scope vulnerability, please email securityreporting@optum.com” “The following types of vulnerabilities are considered out of the scope for the purposes of this program: Volumetric vulnerabilities (e.g., Denial of Service or Distributed DoS); Reports of non-exploitable vulnerabilities...” “The time to address a valid, reported vulnerability will vary based on impact of the potential vulnerability and affected systems.” “For the security of our customers, UnitedHealth Group will not disclose, discuss, or confirm security issues.” “Security researchers must not violate any law, or access, use, alter or compromise in any manner any UnitedHealth Group data.” | |||||||
| 4 | Apple apple.com |
✓ | Bounty | L2 | L2 | match | ▸ |
|
Basic VDP policy text · confidence high
“For Product categories, the issue must affect the latest publicly available version (including beta versions) of iOS, iPadOS, macOS, tvOS, visionOS, or watchOS, with a standard configuration and on publicly available Apple hardware or Security Research Device.” “For Services, the issue must relate to a web server or service owned by Apple or an Apple subsidiary.” “Submit your report online to help ensure that you receive timely updates, can add additional information as needed, and can communicate with Apple security engineers about your report.” “We make it a priority to resolve security and privacy issues as quickly as possible, and most reports are resolved within 90 days.” “Publicly disclosing security issues before a fix is available makes you ineligible for all Apple Security Bounty rewards.” | |||||||
| 5 | Alphabet attr? google.com |
✓ | Bounty | L2 | L2 | — | ▸ |
|
Basic VDP directory parse
No policy text graded — see provenance.
Source: directory: safeHarbor=None
| |||||||
| 6 | CVS Health cvshealth.com |
— | VDP | L2 | — | new | ▸ |
|
Basic VDP policy text · confidence high
“we encourage you to report it by using this page. Your report will be forwarded for timely acknowledgement and verification. Verified issues will then be passed to our development teams for remediation on a timeline commensurate with the severity of the issue.” “Any exfiltration or downloading of CVS Health/Aetna data, disclosure of confidential information, and/or disrupting our customers' experience are all outside the scope of this program and outside any protections it affords from legal recourse.” “You are expected to engage in security research responsibly.” “Per our policy, if you wish to take part in the CVS Health Vulnerability Disclosure Program, you are expected to follow these guidelines” | |||||||
| 7 | Berkshire Hathaway berkshirehathaway.com |
— | — | L0 | — | — | ▸ |
|
Not Present none
No policy text graded — see provenance.
Source: —
| |||||||
| 8 | McKesson mckesson.com |
✓ | VDP | L2 | — | new | ▸ |
|
Basic VDP policy text · confidence high
“please submit it in the form below or email VulnerabilityReporting@McKesson.com” “We will contact you to confirm that we've received your report and trace your steps to reproduce your research. We will work with the affected teams to validate the report. We will notify you of remediation” “Do not hack, penetrate, or attempt to gain access to McKesson infrastructure, systems, or data” “you agree to comply with McKesson's Terms of Service, McKesson's Privacy Policy, and all applicable state, federal, or international laws and regulations” “you may not publicly disclose your findings or the contents of your Submission to any third parties. McKesson's program does not permit disclosure to any party outside of McKesson” ⚠ VDP/reporting: submitted NO, verified YES
| |||||||
| 9 | Exxon Mobil exxonmobil.com |
— | — | L0 | — | — | ▸ |
|
Not Present none
No policy text graded — see provenance.
Source: —
| |||||||
| 10 | Cencora cencora.com |
— | — | L0 | — | — | ▸ |
|
Not Present none
No policy text graded — see provenance.
Source: —
| |||||||
| 11 | Microsoft microsoft.com |
✓ | Bounty | L2 | L2 | match | ▸ |
|
Basic VDP policy text · confidence high
“Microsoft Bounty Program is subject to these terms and those outlined in the Microsoft Bounty Terms and Conditions , Microsoft Bounty Legal Safe Harbor , Rules of Engagement , Bounty Program Guidelines” “Cloud Programs Up to $100,000 USD ... Endpoint & On-Prem Programs Up to $250,000 USD ... Zero Day Quest Up to $100,000 USD” “Report vulnerabilities privately and allow time for remediation before public disclosure. Adhere to our Rules of Engagement and program scope to ensure eligibility for awards.” “Do not access, modify, or exfiltrate customer data. Never disrupt services or compromise uptime.” | |||||||
| 12 | JPMorgan Chase jpmorganchase.com |
— | VDP | L2 | — | new | ▸ |
|
Basic VDP policy text · confidence high
“Typical Vulnerabilities Accepted: OWASP Top 10 vulnerability categories Other vulnerabilities with demonstrated impact” “Typical Out of Scope: Theoretical vulnerabilities Informational disclosure of non-sensitive data Low impact session management issues Self XSS (user defined payload)” “Work directly with the JPMorgan Chase Responsible Disclosure Program on vulnerability submissions” “you will be allowed to disclose the vulnerability after a fix has been issued” “Adhere to all legal terms and conditions outlined at ResponsibleDisclosure.JPMorganChase.com” | |||||||
| 13 | Costco Wholesale costco.com |
✓ | Contact | L1 | — | — | ▸ |
|
Contact Only channel presence
No policy text graded — see provenance.
Source: —
| |||||||
| 14 | Cigna Group cigna.com |
— | Contact | L1 | — | — | ▸ |
|
Contact Only channel presence
No policy text graded — see provenance.
Source: —
| |||||||
| 15 | Cardinal Health cardinalhealth.com |
— | — | L0 | — | — | ▸ |
|
Not Present none
No policy text graded — see provenance.
Source: —
⚠ VDP/reporting: submitted YES, verified NO
| |||||||
| 16 | Nvidia nvidia.com |
— | VDP | L2 | — | new | ▸ |
|
Basic VDP policy text · confidence medium
“This is a responsible disclosure program without bounties.” “Your Submission must be for an Asset (herein referred to as "product" and/or "technology") that is identified as in scope of the NVIDIA Program(s).” “You are required to report a discovered Vulnerability in a prompt and transparent manner through the Platform.” “You agree to conduct your research within the bounds of Ethical Hacking.” “You agree to practice coordinated disclosure in all of your security research conducted under the Program” | |||||||
| 17 | Meta Platforms attr? meta.com |
✓ | Bounty | L2 | L2 | — | ▸ |
|
Basic VDP directory parse
No policy text graded — see provenance.
Source: directory: safeHarbor=None
| |||||||
| 18 | Elevance Health elevancehealth.com |
— | — | L0 | — | — | ▸ |
|
Not Present none
No policy text graded — see provenance.
Source: —
| |||||||
| 19 | Centene centene.com |
— | — | L0 | — | — | ▸ |
|
Not Present none
No policy text graded — see provenance.
Source: —
| |||||||
| 20 | Bank of America bankofamerica.com |
— | Contact | L1 | — | — | ▸ |
|
Contact Only channel presence
No policy text graded — see provenance.
Source: —
⚠ VDP/reporting: submitted NO, verified YES
| |||||||
| 21 | Chevron chevron.com |
— | — | L0 | — | — | ▸ |
|
Not Present none
No policy text graded — see provenance.
Source: —
| |||||||
| 22 | Ford Motor ford.com |
— | — | L0 | — | — | ▸ |
|
Not Present none
No policy text graded — see provenance.
Source: —
| |||||||
| 23 | General Motors gm.com |
— | — | L0 | — | — | ▸ |
|
Not Present none
No policy text graded — see provenance.
Source: —
⚠ VDP/reporting: submitted YES, verified NO
| |||||||
| 24 | Citigroup attr? citi.com |
— | Contact | L1 | — | — | ▸ |
|
Contact Only channel presence
No policy text graded — see provenance.
Source: —
| |||||||
| 25 | Home Depot homedepot.com |
— | — | L0 | — | — | ▸ |
|
Not Present none
No policy text graded — see provenance.
Source: —
| |||||||
| 26 | Fannie Mae fanniemae.com |
— | — | L0 | — | — | ▸ |
|
Not Present none
No policy text graded — see provenance.
Source: —
⚠ VDP/reporting: submitted YES, verified NO
| |||||||
| 27 | Kroger kroger.com |
— | Contact | L1 | — | — | ▸ |
|
Contact Only channel presence
No policy text graded — see provenance.
Source: —
| |||||||
| 28 | Verizon verizon.com |
— | — | L0 | — | — | ▸ |
|
Not Present none
No policy text graded — see provenance.
Source: —
⚠ VDP/reporting: submitted YES, verified NO
| |||||||
| 29 | Phillips 66 phillips66.com |
— | — | L0 | — | — | ▸ |
|
Not Present none
No policy text graded — see provenance.
Source: —
| |||||||
| 30 | Marathon Petroleum marathonpetroleum.com |
— | — | L0 | — | — | ▸ |
|
Not Present none
No policy text graded — see provenance.
Source: —
| |||||||
| 31 | StoneX Group stonex.com |
✓ | VDP | L2 | L2 | — | ▸ |
|
Basic VDP directory parse
No policy text graded — see provenance.
Source: directory: safeHarbor=None
⚠ VDP/reporting: submitted NO, verified YES
| |||||||
| 32 | State Farm statefarm.com |
✓ | Bounty | L3 | — | new | ▸ |
|
Partial Safe Harbor policy text · confidence high
“State Farm will not take legal action against you or revoke access to State Farm applications” “If you have noticed an information security issue in a State Farm system while using www.statefarm.com or a State Farm mobile application, we want to hear about it” “Please disclose issues using the Vulnerability Disclosure Communication form located on this web page” “State Farm will work to address the issue in a timely fashion” “We reserve all legal rights in the event of noncompliance” | |||||||
| 33 | Freddie Mac freddiemac.com |
— | — | L0 | — | — | ▸ |
|
Not Present none
No policy text graded — see provenance.
Source: —
⚠ VDP/reporting: submitted YES, verified NO
| |||||||
| 34 | Humana humana.com |
— | VDP | L2 | L2 | — | ▸ |
|
Basic VDP directory parse
No policy text graded — see provenance.
Source: directory: safeHarbor=None
⚠ security.txt: submitted YES, verified NO; VDP/reporting: submitted NO, verified YES
| |||||||
| 35 | AT&T att.com |
— | Contact | L1 | — | — | ▸ |
|
Contact Only channel presence
No policy text graded — see provenance.
Source: —
| |||||||
| 36 | Goldman Sachs goldmansachs.com |
— | Contact | L1 | — | — | ▸ |
|
Contact Only channel presence
No policy text graded — see provenance.
Source: —
| |||||||
| 37 | Comcast xfinity.com |
— | Contact | L1 | — | — | ▸ |
|
Contact Only channel presence
No policy text graded — see provenance.
Source: —
| |||||||
| 38 | Wells Fargo wellsfargo.com |
— | Contact | L1 | — | — | ▸ |
|
Contact Only channel presence
No policy text graded — see provenance.
Source: —
| |||||||
| 39 | Morgan Stanley morganstanley.com |
— | VDP | L2 | — | new | ▸ |
|
Basic VDP policy text · confidence high
“Typical Vulnerabilities Accepted: OWASP Top 10 vulnerability categories Other vulnerabilities with demonstrated impact” “Typical Out of Scope: Theoretical vulnerabilities Informational disclosure of non-sensitive data Low impact session management issues Self XSS (user defined payload)” “To work directly with ResponsibleDisclosure.com on vulnerability submissions in good faith” “you will be allowed to disclose the vulnerability after a fix has been issued” “Not to engage in disruptive testing like DoS or any action that could impact the confidentiality, integrity or availability of information and systems” | |||||||
| 40 | Valero Energy valero.com |
— | — | L0 | — | — | ▸ |
|
Not Present none
No policy text graded — see provenance.
Source: —
| |||||||
| 41 | Dell Technologies dell.com |
✓ | Contact | L1 | L2 | ±1 | ▸ |
|
Contact Only policy text · confidence high
“Contact: https://www.dell.com/support/dell-vulnerability-response-policy # Bug Bounty Program - Applications” “Contact: https://bugcrowd.com/dell-com # Bug Bounty Program - Products” “Contact: https://bugcrowd.com/dell-product” “Policy: https://www.dell.com/support/dell-vulnerability-response-policy” | |||||||
| 42 | Target target.com |
— | — | L0 | — | — | ▸ |
|
Not Present none
No policy text graded — see provenance.
Source: —
⚠ VDP/reporting: submitted YES, verified NO
| |||||||
| 43 | Tesla tesla.com |
— | Contact | L1 | — | — | ▸ |
|
Contact Only channel presence
No policy text graded — see provenance.
Source: —
⚠ security.txt: submitted YES, verified NO
| |||||||
| 44 | Walt Disney disney.com |
— | Contact | L1 | — | — | ▸ |
|
Contact Only channel presence
No policy text graded — see provenance.
Source: —
| |||||||
| 45 | Johnson & Johnson jnj.com |
— | — | L0 | — | — | ▸ |
|
Not Present none
No policy text graded — see provenance.
Source: —
⚠ VDP/reporting: submitted YES, verified NO
| |||||||
| 46 | PepsiCo pepsico.com |
— | Contact | L1 | — | — | ▸ |
|
Contact Only channel presence
No policy text graded — see provenance.
Source: —
| |||||||
| 47 | Boeing boeing.com |
✓ | VDP | L3 | L2 | ±1 | ▸ |
|
Partial Safe Harbor policy text · confidence high
“Boeing will not pursue civil action or initiate a complaint to law enforcement for accidental, good faith violations of this policy.” “We consider activities conducted consistent with this policy to constitute authorized access under anti-hacking laws.” “To the extent your activities are inconsistent with certain Boeing terms and conditions, we waive those restrictions for the limited purpose of permitting security research under this policy.” “Provide Boeing reasonable time to fix any reported issue, before such information is shared with a third party or disclosed publicly.” | |||||||
| 48 | UPS attr? ups.com |
— | Contact | L1 | — | — | ▸ |
|
Contact Only channel presence
No policy text graded — see provenance.
Source: —
| |||||||
| 49 | RTX attr? rtx.com |
— | — | L0 | — | — | ▸ |
|
Not Present none
No policy text graded — see provenance.
Source: —
⚠ VDP/reporting: submitted YES, verified NO
| |||||||
| 50 | FedEx fedex.com |
— | — | L0 | — | — | ▸ |
|
Not Present none
No policy text graded — see provenance.
Source: —
⚠ VDP/reporting: submitted YES, verified NO
| |||||||
| 51 | Progressive progressive.com |
— | — | L0 | — | — | ▸ |
|
Not Present none
No policy text graded — see provenance.
Source: —
| |||||||
| 52 | Lowe's lowes.com |
— | Contact | L1 | — | — | ▸ |
|
Contact Only channel presence
No policy text graded — see provenance.
Source: —
| |||||||
| 53 | Energy Transfer energytransfer.com |
— | — | L0 | — | — | ▸ |
|
Not Present none
No policy text graded — see provenance.
Source: —
| |||||||
| 54 | Procter & Gamble pg.com |
✓ | VDP | L4 | — | new | ▸ |
|
Full Safe Harbor policy text · confidence high
“we consider this research conducted under this policy to be: Authorized concerning any applicable anti-hacking laws, and we will not initiate or support legal action against you for accidental, good-faith violations of this policy” “Authorized concerning any relevant anti-circumvention laws, and we will not bring a claim against you for circumvention of technology controls” “Exempt from restrictions in our Terms of Service (TOS) and/or Acceptable Usage Policy (AUP) that would interfere with conducting security research, and we waive those restrictions on a limited basis” “Public disclosure may be allowed upon request, and only after granted written permission to do so from P&G” Source: https://vdp.pg.com
| |||||||
| 55 | Sysco sysco.com |
— | — | L0 | — | — | ▸ |
|
Not Present none
No policy text graded — see provenance.
Source: —
| |||||||
| 56 | American Express americanexpress.com |
✓ | Contact | L1 | — | — | ▸ |
|
Contact Only channel presence
No policy text graded — see provenance.
Source: —
⚠ security.txt: submitted NO, verified YES
| |||||||
| 57 | Albertsons albertsons.com |
— | — | L0 | — | — | ▸ |
|
Not Present none
No policy text graded — see provenance.
Source: —
⚠ VDP/reporting: submitted YES, verified NO
| |||||||
| 58 | Archer Daniels Midland adm.com |
— | — | L0 | — | — | ▸ |
|
Not Present none
No policy text graded — see provenance.
Source: —
| |||||||
| 59 | MetLife attr? metlife.com |
— | — | L0 | — | — | ▸ |
|
Not Present none
No policy text graded — see provenance.
Source: —
⚠ VDP/reporting: submitted YES, verified NO
| |||||||
| 60 | HCA Healthcare attr? hcahealthcare.com |
✓ | VDP | L2 | L2 | match | ▸ |
|
Basic VDP policy text · confidence medium
“please let us know by emailing our Information Protection & Security team directly at Information.Protection@hcahealthcare.com” “We ask that you work with us to diagnose and correct a vulnerability prior to publically disclosing it to ensure the safety and wellbeing of our patients and systems” “We ask that you not perform vulnerability or similar testing on products that are actively in use for public safety reasons” “In the event you share information with us, you agree that the information you submit will be considered non-proprietary and non-confidential, and that we may use such information in any manner, without restriction. Furthermore, you agree that submitting information does not create any rights for you or any obligation for us.” | |||||||
| 61 | Lockheed Martin lockheedmartin.com |
— | Contact | L1 | — | — | ▸ |
|
Contact Only channel presence
No policy text graded — see provenance.
Source: —
| |||||||
| 62 | New York Life newyorklife.com |
— | — | L0 | — | — | ▸ |
|
Not Present none
No policy text graded — see provenance.
Source: —
| |||||||
| 63 | Capital One capitalone.com |
✓ | Bounty | L3 | — | new | ▸ |
|
Partial Safe Harbor policy text · confidence high
“By responsibly submitting your findings to Capital One in accordance with these guidelines Capital One agrees not to pursue legal action against you.” “Capital One reserves all legal rights in the event of noncompliance with these guidelines.” “Do not engage in any activity that violates (a) federal or state laws or regulations or (b) the laws or regulations of any country where (i) data, assets or systems reside, (ii) data traffic is routed or (iii) the researcher is conducting research activity.” “Provide Capital One reasonable time to fix any reported issue.” “Out of Scope Vulnerabilities Certain vulnerabilities are considered out of scope for our Responsible Disclosure Program.” | |||||||
| 64 | Allstate allstate.com |
— | Contact | L1 | — | — | ▸ |
|
Contact Only channel presence
No policy text graded — see provenance.
Source: —
| |||||||
| 65 | Caterpillar caterpillar.com |
— | Contact | L1 | — | — | ▸ |
|
Contact Only channel presence
No policy text graded — see provenance.
Source: —
⚠ security.txt: submitted YES, verified NO
| |||||||
| 66 | IBM attr? ibm.com |
✓ | Contact | L1 | L2 | ±1 | ▸ |
|
Contact Only policy text · confidence high
“Contact: https://www.ibm.com/trust/security-psirt” “Contact: https://hackerone.com/ibm?type=team” “Contact: mailto:psirt@us.ibm.com” “PSIRT manages Product, Website, Secrets / Tokens Vulnerabilities” | |||||||
| 67 | Eli Lilly lilly.com |
— | — | L0 | — | — | ▸ |
|
Not Present none
No policy text graded — see provenance.
Source: —
⚠ VDP/reporting: submitted YES, verified NO
| |||||||
| 68 | Merck merck.com |
— | VDP | L2 | L2 | — | ▸ |
|
Basic VDP directory parse
No policy text graded — see provenance.
Source: directory: safeHarbor=None
| |||||||
| 69 | Nationwide nationwide.com |
✓ | VDP | L2 | — | new | ▸ |
|
Basic VDP policy text · confidence high
“vulnerabilitydisclosure@nationwide.co.uk” “You must not: Break any applicable law or regulations. Access unnecessary, excessive or significant amounts of data. Modify data in Nationwide's systems or services.” “Submissions we won't respond to: Vulnerabilities relating to systems, websites or apps which are not owned or controlled by us.” “We do not offer financial compensation or any other form of reward for submissions.” “By emailing or providing a disclosure to us, you agree to our terms.” “We will review all submissions that meet the requirements listed on this page.” ⚠ security.txt: submitted NO, verified YES
| |||||||
| 70 | Broadcom broadcom.com |
— | — | L0 | — | — | ▸ |
|
Not Present none
No policy text graded — see provenance.
Source: —
⚠ VDP/reporting: submitted YES, verified NO
| |||||||
| 71 | Delta Air Lines delta.com |
— | — | L0 | — | — | ▸ |
|
Not Present none
No policy text graded — see provenance.
Source: —
⚠ security.txt: submitted YES, verified NO; VDP/reporting: submitted YES, verified NO
| |||||||
| 72 | Publix Super Markets publix.com |
— | — | L0 | — | — | ▸ |
|
Not Present none
No policy text graded — see provenance.
Source: —
| |||||||
| 73 | Pfizer pfizer.com |
— | Contact | L1 | — | — | ▸ |
|
Contact Only channel presence
No policy text graded — see provenance.
Source: —
| |||||||
| 74 | TD Synnex tdsynnex.com |
— | — | L0 | — | — | ▸ |
|
Not Present none
No policy text graded — see provenance.
Source: —
| |||||||
| 75 | ConocoPhillips conocophillips.com |
— | — | L0 | — | — | ▸ |
|
Not Present none
No policy text graded — see provenance.
Source: —
| |||||||
| 76 | Galaxy Digital galaxy.com |
✓ | VDP | L2 | L2 | — | ▸ |
|
Basic VDP directory parse
No policy text graded — see provenance.
Source: directory: safeHarbor=None
⚠ VDP/reporting: submitted NO, verified YES
| |||||||
| 77 | AbbVie abbvie.com |
— | — | L0 | — | — | ▸ |
|
Not Present none
No policy text graded — see provenance.
Source: —
⚠ VDP/reporting: submitted YES, verified NO
| |||||||
| 78 | Prudential Financial prudential.com |
— | — | L0 | — | — | ▸ |
|
Not Present none
No policy text graded — see provenance.
Source: —
| |||||||
| 79 | TJX attr? tjx.com |
✓ | Contact | L1 | — | — | ▸ |
|
Contact Only channel presence
No policy text graded — see provenance.
Source: —
⚠ VDP/reporting: submitted NO, verified YES
| |||||||
| 80 | Performance Food pfgc.com |
— | — | L0 | — | — | ▸ |
|
Not Present none
No policy text graded — see provenance.
Source: —
| |||||||
| 81 | United Airlines united.com |
— | Contact | L1 | — | — | ▸ |
|
Contact Only channel presence
No policy text graded — see provenance.
Source: —
⚠ security.txt: submitted YES, verified NO
| |||||||
| 82 | Oracle oracle.com |
— | Contact | L1 | — | — | ▸ |
|
Contact Only channel presence
No policy text graded — see provenance.
Source: —
| |||||||
| 83 | Cisco Systems cisco.com |
✓ | Bountypartial | L2 | L2 | match | ▸ |
|
Basic VDP policy text · confidence medium
“The Cisco PSIRT is a dedicated, global team that receives, investigates, and publicly reports information about security vulnerabilities and issues related to Cisco products and services.” “Cisco welcomes reports from independent researchers, industry organizations, vendors, customers, and other sources concerned with product or network security.” “Throughout the investigative process, the Cisco PSIRT strives to work collaboratively with the incident reporter to assess the nature of the vulnerability, gather required technical information, and determine appropriate remedial action.” “The Cisco PSIRT asks incident reporters to maintain strict confidentiality until complete resolutions are available for customers and have been published by the Cisco PSIRT on the Cisco website through the appropriate coordinated disclosure.” “The Cisco PSIRT aligns its practices with ISO/IEC 29147:2018, which are guidelines for disclosure of potential vulnerabilities established by the International Organization for Standardization.” | |||||||
| 84 | HP attr? hp.com |
✓ | Contact | L1 | — | — | ▸ |
|
Contact Only channel presence
No policy text graded — see provenance.
Source: —
| |||||||
| 85 | Charter Communications corporate.charter.com |
— | — | L0 | — | — | ▸ |
|
Not Present none
No policy text graded — see provenance.
Source: —
| |||||||
| 86 | American Airlines aa.com |
— | — | L0 | — | — | ▸ |
|
Not Present none
No policy text graded — see provenance.
Source: —
⚠ VDP/reporting: submitted YES, verified NO
| |||||||
| 87 | Tyson Foods tysonfoods.com |
— | — | L0 | — | — | ▸ |
|
Not Present none
No policy text graded — see provenance.
Source: —
| |||||||
| 88 | Intel intel.com |
— | Bounty | L3 | L2 | ±1 | ▸ |
|
Partial Safe Harbor policy text · confidence medium
“To provide reasonable safe harbor to researchers following all Rules of Engagement . See " Safe Harbor " section.” “Intel Corporation believes that forging relationships with security researchers and fostering security research is a crucial part of our Security First Pledge. We encourage security researchers to work with us to mitigate and coordinate the disclosure of potential security vulnerabilities.” “You will not discuss or disclose vulnerability information with anyone not authorized by Intel without prior written consent from Intel” ⚠ security.txt: submitted YES, verified NO
| |||||||
| 89 | Enterprise Products enterpriseproducts.com |
— | — | L0 | — | — | ▸ |
|
Not Present none
No policy text graded — see provenance.
Source: —
| |||||||
| 90 | Ingram Micro ingrammicro.com |
— | — | L0 | — | — | ▸ |
|
Not Present none
No policy text graded — see provenance.
Source: —
| |||||||
| 91 | General Dynamics gd.com |
— | — | L0 | — | — | ▸ |
|
Not Present none
No policy text graded — see provenance.
Source: —
| |||||||
| 92 | Uber Technologies uber.com |
— | Contact | L1 | — | — | ▸ |
|
Contact Only channel presence
No policy text graded — see provenance.
Source: —
| |||||||
| 93 | USAA usaa.com |
— | Contact | L1 | L2 | ±1 | ▸ |
|
Contact Only policy text · confidence high
“Contact: https://bugcrowd.com/engagements/usaa” “Contact: mailto:disclosure@usaa.com” “Policy: https://bugcrowd.com/usaa” | |||||||
| 94 | TIAA tiaa.org |
— | — | L0 | — | — | ▸ |
|
Not Present none
No policy text graded — see provenance.
Source: —
| |||||||
| 95 | Liberty Mutual Insurance libertymutualgroup.com |
— | — | L0 | — | — | ▸ |
|
Not Present none
No policy text graded — see provenance.
Source: —
| |||||||
| 96 | Travelers travelers.com |
— | Bounty | L3 | — | new | ▸ |
|
Partial Safe Harbor policy text · confidence high
“Synack commits that, if we conclude, in our sole discretion, that a security vulnerability submitted through our Site complies with the Terms of Use, the applicable Scope and Rules of Engagement and the applicable Responsible Disclosure Guidelines, Synack will not bring a private action against you or refer the matter for public inquiry.” “The following web applications are in scope: *.travelers.com” “If you submit a valid vulnerability, you will be notified after a fix has been issued, and you will have the opportunity to be added to the Acknowledgments page and to disclose the vulnerability.” “Adhere to these Guidelines and the Rules of Engagement and Scope, and do not engage in disruptive testing like DoS or any action that could impact the confidentiality, integrity or availability of Travelers' information and systems.” | |||||||
| 97 | Bristol-Myers Squibb bms.com |
— | — | L0 | — | — | ▸ |
|
Not Present none
No policy text graded — see provenance.
Source: —
| |||||||
| 98 | Coca-Cola coca-cola.com |
— | VDP | L3 | — | new | ▸ |
|
Partial Safe Harbor policy text · confidence high
“Safe harbour for researchers is applied” “with the exception of what is listed as explicitly out-of-scope you are welcome and encouraged to submit impactful findings on any asset you can attribute to The Coca-Cola Company or our brands!” “Not discuss or disclose vulnerability information without prior written consent (including PoC's on YouTube and Vimeo)” | |||||||
| 99 | Nike about.nike.com |
— | Contact | L1 | — | — | ▸ |
|
Contact Only channel presence
No policy text graded — see provenance.
Source: —
| |||||||
| 100 | Massachusetts Mutual massmutual.com |
— | — | L0 | — | — | ▸ |
|
Not Present none
No policy text graded — see provenance.
Source: —
⚠ VDP/reporting: submitted YES, verified NO
| |||||||
Pipeline. Each company's domain was resolved through lookup.disclose.io — which checks /.well-known/security.txt, the disclose.io directory, and the major bug-bounty platforms — to find every reporting channel and policy URL. Where a policy page was reachable, its actual text was graded independently against the six-level disclose.io Maturity Model, looking for the specific signals that separate the levels: a promise not to pursue legal action (L3), explicit authorization to test plus CFAA / DMCA / Terms-of-Service carve-outs (L4), and a coordinated-disclosure deadline (L5).
Provenance is labelled per row. policy text = graded from the company's own published policy. directory parse = the policy sits on a platform we couldn't read as plain text, so the disclose.io directory's safe-harbor classification stands in. channel presence = a reporting channel exists but no policy was gradeable. The "Dir." column is the directory's safe-harbor class; a flag marks where our independent read differs.
Caveats. This is a point-in-time snapshot (2026-06-20); policies change. Attribution can land on a subsidiary for conglomerates (flagged attr?). "Submitted vs verified" corrections are listed on each affected row.