Information submitted under this policy will be used for defensive purposes only – to mitigate or remediate vulnerabilities.
We accept vulnerability reports via this form.
If your findings include newly discovered vulnerabilities that affect all users of a product or service and not solely USPTO, we may share your report with the Cybersecurity and Infrastructure Security Agency, where it will be handled under their coordinated vulnerability disclosure process. We will not share your name or contact information without express permission, except for disclosures required by law.
Reports may be submitted anonymously. If you share contact information, we will acknowledge receipt of your report within 3 business days.
By submitting a vulnerability, you acknowledge that you have no expectation of payment and that you expressly waive any future pay claims against the U.S. Government related to your submission.
What we would like to see from you
- Provide the location (hostname/URL) the vulnerability was discovered and the potential impact of exploitation.
- Offer a detailed description of the steps needed to reproduce the vulnerability (proof of concept scripts or screenshots are helpful).
- Provide us 90 calendar days to resolve the issue before you disclose it publicly.
- If you decide to publicly disclose a vulnerability, after the 90 calendar days, provide us 7 business day notice prior to public disclosure
- Be in English, if possible.
What you can expect from us
When you choose to share your contact information with us, we commit to coordinating with you as openly and as quickly as possible in a manner that is consistent with applicable law.Within three business days, we will acknowledge receipt of your report.
- Within 3 business days, we will acknowledge that your report has been received.
- To the best of our ability, we will confirm the existence of the vulnerability to you within 90 days. We will be as transparent as possible about what steps we are taking during the remediation process, including on issues or challenges that may delay resolution.
- We will maintain an open dialogue to discuss issues.
Questions regarding this policy may be sent to firstname.lastname@example.org.