Cybersecurity & vendor risk
Responsible disclosure
A vendor’s published process for how outside researchers should report a security vulnerability, rather than disclosing it publicly or exploiting it. See security.txt, the standard machine-readable file format for publishing this.