PenFed Credit Union Vulnerability Disclosure | Synack

PenFed Vulnerability Disclosure

Protect PenFed by reporting security vulnerabilities through our Vulnerability Disclosure Program (VDP). Submit findings securely and support a transparent, proactive security process.

Overview

This Responsible Disclosure Program (the “Program”) page is for security researchers interested in reporting application security vulnerabilities. This page is intended for application security vulnerabilities only.

Vulnerabilities submitted to the Program through the form provided will be reviewed by Synack, Inc. (“Synack”), an independent third party. Submissions will be reviewed by Synack to confirm they are within the Program scope and a valid security issue, and Synack will only share vulnerabilities they’ve verified with PenFed Credit Union. If you submit a valid vulnerability, you will be notified after a fix has been issued, and you will have the opportunity to be added to the Acknowledgments page and to disclose the vulnerability. The submission review and validation process is managed exclusively by Synack through their platform and you must follow the Guidelines and Rules of Engagement and Scope set forth below to participate. All submissions and queries regarding the Program should be submitted directly to Synack using the link below.

Guidelines

In submitting a request, you agree to all of the following:

The following web applications are in scope: *.penfed.org.

Rules of Engagement

Out of Scope – Low Impact Vulnerabilities

The following vulnerabilities are considered too low of an impact to the client and would be marked as Out of Scope if submitted:

Additional specific vulnerability types considered out of scope due to low impact:

Company Information

Company Name
PenFed Credit Union
Website
https://www.penfed.org/
About
Pentagon Federal Credit Union (PenFed) is America's second-largest federal credit union, serving 2.9 million members worldwide with over $31 billion in assets.