United States Patent and Trademark Office - Vulnerability Disclosure Program

  • Safe harbor

We no longer offer point rewards for submissions on this program. Please refer to our blog post: How Bugcrowd sees VDPs and points for more details.

Program stats

  • Vulnerabilities accepted 62
  • Validation within about 23 hours 75% of submissions are accepted or rejected within about 23 hours

Latest hall of famers

Recently joined this program

The strength and vitality of the U.S. economy depends directly on effective mechanisms that protect new ideas and investments in innovation and creativity. The United States Patent and Trademark Office (USPTO) is committed to ensuring that the data stored within all USPTO systems is safe and secure. This commitment can be fulfilled not only by the dedicated staff of the USPTO, but also by external researchers with the right expertise.

We encourage security researchers to contact us when reporting potential vulnerabilities discovered in the systems within the scope of this policy via the methods below.

Ratings/Rewards:

For the initial prioritization/rating of findings, this program will use the Bugcrowd Vulnerability Rating Taxonomy. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.

Scope

Program rules

This program follows Bugcrowd’s standard disclosure terms.

For any testing issues (such as broken credentials, inaccessible application, or Bugcrowd Ninja email problems), please submit through the Bugcrowd Support Portal. We will address your issue as soon as possible.