The Federal Reserve Vulnerability Disclosure | Synack

The Federal Reserve Vulnerability Disclosure Program

Protect The Federal Reserve by reporting security vulnerabilities through our Vulnerability Disclosure Program (VDP). Submit findings securely and support a transparent, proactive security process.

Responsible Disclosure Policy:

This page is for security researchers interested in reporting application security vulnerabilities. This is intended for application security vulnerabilities only.

If you have reported an issue determined to be within program scope, is determined to be a valid security issue, and you have followed program guidelines, your finding will be recognized and you will be allowed to disclose the vulnerability after a fix has been issued. All submissions and queries regarding the Program should be submitted through the Submission Form.

Federal Reserve Disclosure Policy

The Federal Reserve commits to acknowledging disclosed vulnerabilities promptly and working with the security research community to mitigate or remediate weaknesses.

The Federal Reserve asks participating security researchers to:

Program Rules

Typical Vulnerabilities Accepted

Typical Out of Scope

Responsible Disclosure Guidelines

Safe Harbor

We understand the reluctance some researchers have to share information about vulnerabilities they find because of the potential for criminal or civil liability. To encourage responsible research and disclosure of security vulnerabilities, we do not intend to assert claims under the Computer Fraud and Abuse Act or claims of trespass or similar legal theories against researchers who undertake in good faith to test our systems for vulnerabilities and who bring their findings promptly to our attention. You are expected, as always, to comply with all laws applicable to you and not to disrupt or compromise any data beyond what this VDP permits.

We reserve the right in our sole discretion to determine whether your actions are taken in good faith, are consistent with this policy, or are an inadvertent violation. Please contact us before engaging in conduct that you think may be inconsistent with or unaddressed by this policy. Your efforts to proactively contact us before engaging in any action inconsistent with or unaddressed by this policy will be an important factor in our determination.

Thank you for helping keep the Federal Reserve and our users safe!

Responsible Disclosure Rules of Engagement

In-Scope Targets

Any publicly-accessible system owned, operated, or controlled by the Federal Reserve System or Federal Reserve Banks, including any Federal Reserve owned web applications or services hosted on those systems.

Federal Reserve Bank sites use non-government top-level domains such as .com, .org, .net, etc.

Federal Reserve Bank domains include, but are not limited to:

Out-of-Scope Targets

This VDP applies to the private sector Federal Reserve Banks (generally .com and .org sites) and not the public sector Federal Reserve Board of Governors (.gov sites).

The following are beyond the scope of this VDP:

Activities

In-Scope Activities

Activities are limited exclusively to:

All testing activities should abide by relevant laws

Header identification:

Sometimes abnormal traffic can be considered malicious. Please provide the following header to allow us to correctly identify your traffic:

Out-of-Scope Activities

Vulnerabilities

In-Scope Vulnerabilities

All vulnerabilities are in scope for disclosure excepting those explicitly listed as out-of-scope below.

Out-of-Scope Vulnerabilities

When reporting vulnerabilities, please consider (1) attack scenario / exploitability, and (2) security impact of the bug. The following issues are considered out of scope:

Low Impact Vulnerabilities – Out of Scope

The following vulnerabilities are considered too low of an impact to the client and would be marked as Out of Scope if submitted:

Additional specific vulnerability types considered out of scope due to low impact:

I. Overview

The following terms of use (the “Terms of Use”) apply when you view or use the Responsible Disclosure Program (the “Program”) hosted by Synack, Inc. (“Synack”, “we”, “our”, “us”) on Synack’s website at synack.com (https://www.synack.com/vdp/the-federal-reserve/)  (our “Site”). By using our Site, you agree to fully comply with and be bound by the Terms of Use. By using our Site, you agree to fully comply with and be bound by the Terms of Use. Please review them carefully. If you do not accept our Terms of Use, do not access and use our Site. If you have already accessed our Site and do not accept our Terms of Use, you should immediately discontinue use of our Site. Synack commits that, if we conclude, in our sole discretion, that a security vulnerability submitted through the Site complies with the Terms of Use and the applicable Responsible Disclosure Guidelines, Synack will not bring a private action against you or refer the matter for public inquiry

II. Privacy Policy

We respect the privacy of our Site visitors. Please refer to our Privacy Policy which explains how we collect, use, and disclose information that pertains to your privacy. When you access or use the Site, you signify your agreement to this Privacy Policy.

III. Eligibility Requirements

You agree that you will not under any circumstances:

If we discover that you do not meet any of the criteria above, we will remove you from the Program. Any submissions you make to the Program, whether via the Program, in communications regarding an existing ticket for an existing submission , or by email shall be considered “Submission(s)” for purposes of these Terms of Use.

IV. Posting and Conduct Restrictions

By transmitting any Submission while using the Site, you agree, represent and warrant as follows:

V. Access Limitation; Appropriate Action

We reserve the right, but are not obligated, to limit or deny access to the Site and to take other appropriate action if a user violates these Terms of Use or engages in any activity that violates the rights of any person or entity or which we deem unlawful, offensive, abusive, harmful or malicious.

VI. License Grant

By transmitting your submission to the Program, you perpetually allow us and our affiliates and subsidiaries the unconditional ability to use, modify, create derivative work from, distribute, disclose and store the information provided in your report or to have others do the same on our behalf, and these rights cannot be revoked. You represent that the report is original to you and that you own all right, title and interest in the submission.

VII. Intellectual Property

You acknowledge and agree that we and our licensors retain ownership of all intellectual property rights of any kind related to the Site, including applicable copyrights, trademarks and other proprietary rights. Other product and company names that are mentioned on the Site may be trademarks of their respective owners. We reserve all rights that are not expressly granted to you in the Terms of Use.

VIII. Disclaimer; Limitation of Damages; Release

OUR SITE IS PROVIDED “AS IS” WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING ANY WARRANTY OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, SECURITY, ACCURACY AND NON-INFRINGEMENT. WITHOUT LIMITING THE FOREGOING, WE MAKE NO WARRANTY OR REPRESENTATION THAT ACCESS TO OR OPERATION OF THE SITE WILL BE UNINTERRUPTED OR ERROR FREE. YOU ASSUME FULL RESPONSIBILITY AND RISK OF LOSS RESULTING FROM YOUR DOWNLOADING AND/OR USE OF FILES, INFORMATION, CONTENT OR OTHER MATERIAL OBTAINED FROM THE SITE. TO THE EXTENT PERMITTED BY LAW, IN NO EVENT SHALL WE, OUR AFFILIATES, DIRECTORS, EMPLOYEES OR ITS LICENSORS OR PARTNERS BE LIABLE FOR ANY DIRECT, INDIRECT, PUNITIVE, INCIDENTAL, SPECIAL, CONSEQUENTIAL OR EXEMPLARY DAMAGES, INCLUDING WITHOUT LIMITATION DAMAGES FOR LOSS OF PROFITS, GOODWILL, USE, DATA OR OTHER INTANGIBLE LOSSES, THAT RESULT FROM (A) THE USE, DISCLOSURE, OR DISPLAY OF YOUR INFORMATION OR CONTENT; (B) YOUR USE OR INABILITY TO USE THE SITE; (C) THE SITE GENERALLY OR THE SOFTWARE OR SYSTEMS THAT MAKE THE SITE AVAILABLE; OR (D) ANY OTHER INTERACTIONS WITH THE SITE OR ANY OTHER USER OF THE SITE, WHETHER BASED ON WARRANTY, CONTRACT, TORT (INCLUDING NEGLIGENCE) OR ANY OTHER LEGAL THEORY, WHETHER OR NOT WE HAVE BEEN INFORMED OF THE POSSIBILITY OF SUCH DAMAGE, AND EVEN IF A REMEDY SET FORTH HEREIN IS FOUND TO HAVE FAILED OF ITS ESSENTIAL PURPOSE.

IX. Confidentiality

Any information you receive or collect about us or any of our customers through the Program (“Confidential Information”) must be kept confidential and only used in connection with the ResponsibleDisclosure.com Disclosure Program. You may not use, disclose or distribute any such Confidential Information, including, but not limited to, any information regarding your Submission and information you obtain when researching the sites of our customers, without our prior written consent.

X. Indemnity

You agree to defend, indemnify and hold harmless us, our parent company, officers, directors, employees and agents, from and against any and all claims, damages, obligations, losses, liabilities, costs or debt, and expenses (including but not limited to reasonable attorney’s fees) arising from: (i) your use of and access to the Site; (ii) your violation of any term of these Terms of Use; (iii) your violation of any third party right, including without limitation any copyright, property, or privacy right; or (iv) any claim that any content submitted by you causes damage to a third party. This defense and indemnification obligation will survive these Terms of Use and your use of the Site and the Program.

XI. Modifications of Terms of Use

We can amend these Terms of Use at any time and will update these Terms of Use in the event of any such amendments. It is your sole responsibility to check the Site from time to time to view any such changes. If you continue to access or use the Site, you signify your agreement to our revisions to these Terms of Use.

XII. Applicable Laws; Venue

These Terms of Use and your use of the Site are governed by the federal laws of the United States of America and the laws of the State of California. Any action related to this Site will be filed only in the appropriate state or federal court located within San Mateo County, California. By using this Site, you signify your consent to the jurisdiction of the state and/or federal courts located with San Mateo County, California.

XIII. Suggestions and Feedback

We welcome your feedback and inquiries. If you have any comments or questions, please contact us by sending an email to support@synack.com.

Last updated: January 8, 2025

Company Information

Company Name: The Federal Reserve
Website: https://www.frbservices.org/
About: The Federal Reserve, the central bank of the United States, provides the nation with a safe, flexible, and stable monetary and financial system.