How to answer
Do you have a vulnerability disclosure policy or bug bounty programme?
Very few small companies run a bounty. Almost all of them should have the one-page policy, and it takes an afternoon.
We publish a vulnerability disclosure policy at [your security page], giving a dedicated contact address, a commitment to acknowledge reports within [two] working days, and a safe-harbour statement for good-faith research. We do not currently run a paid bug bounty.
Square brackets are yours to fill in. FillTrust grades an answer like this not in your documents when your documents support it.
- Answered from
- Your security page, your security.txt file, or your responsible disclosure policy.
- Evidence to attach
- The published policy itself, which is a public URL if you have one.
- Where it is asked
- CAIQ v4.0 · TVM-07SIG LiteISO 27001 Annex A · A.8.8
There are two questions inside this one and they get conflated constantly. A bug bounty pays researchers. A vulnerability disclosure policy tells them how to reach you and promises not to sue them. Reviewers care much more about the second, and almost no company under fifty people needs the first.
Say no to the bounty plainly. Paid programmes are expensive in triage time, not just in bounties, and a fifteen-person team running one badly is worse off than one not running it. "We do not currently operate a paid bug bounty programme" is a finished answer.
The disclosure policy is the part worth having, and it is genuinely an afternoon of work. It needs four things: an address that reaches a person, a commitment to acknowledge within a stated time, a statement that you will not pursue legal action against good-faith research within the scope you set, and the scope itself. Publishing it at a predictable location, and adding a security.txt file under /.well-known/, is what makes it findable by the people who would use it.
Safe harbour is the clause that does the work. Without an explicit statement, a researcher who finds a flaw in your product has a real disincentive to report it, and the alternative outcomes are all worse for you. It is two sentences and it is the reason the policy exists.
Answer the response commitment honestly. Two working days to acknowledge is realistic for a small team. Twenty-four hours is not, if the address forwards to somebody on holiday. Whatever you write becomes the thing you are measured against by the next person who reports something.
Where this grades. Usually as not in your documents, because most companies have neither the policy nor a page describing one. That grade is correct and actionable: unlike most gaps on a questionnaire, this one is closed by writing a page rather than by changing how the company operates, and the page then answers this question everywhere it appears.
How this one goes wrong
Specific to this question, not general advice.
- Answering yes for a bug bounty when you mean a security email address. They are different, reviewers know the difference, and the smaller answer is perfectly respectable.
- Publishing an address nobody monitors. This is a promise to respond, and an unread inbox is worse than no policy.
- Omitting safe harbour. Without it, a researcher who finds something has a legal reason not to tell you.