
USPS - United States Postal Service
External Program
Submit bugs directly to this organization


External Program
Submit bugs directly to this organization
This policy is intended to give security researchers clear guidelines for conducting vulnerability discovery activities directed at United States Postal Service (USPS) web properties, and submitting discovered vulnerabilities to USPS.
USPS provides critical services by maintaining a global communication and commerce network. We take our mission seriously and recognize the need to maintain vigilance over our cyber risk to protect the services we provide and the data we hold.
USPS has created a vulnerability disclosure program because we believe your feedback will help us protect the services we provide and keep private data private. We are excited to hear from you on what we need to do to improve.
Information submitted to USPS under this policy will be used for enhancing cybersecurity accessible via our network – to mitigate or remediate vulnerabilities in our networks or applications.
Review, understand, and agree to the following terms and conditions before conducting any testing of USPS networks and before submitting a report. If there is any ambiguity over how to approach a situation that you encounter, please use do no harm as your guiding principle.
Any public-facing website owned, operated, or controlled by USPS, including web applications hosted on those sites.
Provide a detailed summary of the vulnerability, including:
On our side, we will be looking to replicate your findings and remediate based in potential impact.
By clicking Submit Report, you are indicating that you have read, understand, and agree to the guidelines described in this policy for the conduct of security research and disclosure of vulnerabilities or indicators of vulnerabilities related to USPS information systems, and consent to having the contents of the communication and follow-up communications stored on a U.S. Government information system.
USPS will deal in good faith with researchers who discover, test, and submit vulnerabilities or indicators of vulnerabilities in accordance with these guidelines:
Types of activities that are not allowed are:
We take every disclosure seriously and very much appreciate the efforts of security researchers. We will investigate every disclosure and strive to ensure that appropriate steps are taken to mitigate risk and remediate reported vulnerabilities.
USPS provides critical communication and commerce infrastructure for the US economy and the world. We take our responsibility to protect our network seriously and will give your feedback due thought and consideration.
USPS remains committed to coordinating with the researcher as openly and quickly as possible. This includes:
Information submitted to USPS under this policy will be used for defensive purposes – to mitigate or remediate vulnerabilities in our networks or applications, or the applications of our vendors.
USPS does not authorize, permit, or otherwise allow (expressly or impliedly) any person, including any individual, group of individuals, consortium, partnership, or any other business or legal entity to engage in any security research or vulnerability or threat disclosure activity that is inconsistent with this policy. If you engage in any activities that are inconsistent with this policy, you may be subject to criminal and/or civil liabilities.
To the extent that any security research or vulnerability disclosure activity involves the networks, systems, information, applications, products, or services of a non-USPS entity (e.g., other Federal departments or agencies; State, local, or tribal governments; private sector companies or persons; employees or personnel of any such entities; or any other such third party), that non-USPS third party may independently determine whether to pursue legal action or remedies related to such activities.
If you conduct your security research and vulnerability disclosure activities in accordance with the restrictions and guidelines set forth in this policy, (1) USPS will not initiate or recommend any law enforcement or civil lawsuits related to such activities, and (2) in the event of any law enforcement or civil action brought by anyone other than USPS, USPS will take steps to make known that your activities were conducted pursuant to and in compliance with this policy.
USPS may modify the terms of this policy or terminate the policy at any time.
Safe Harbor
Any activities conducted in a manner consistent with this policy will be considered authorized conduct and we will not initiate legal action against you. If legal action is initiated by a third party against you in connection with activities conducted under this policy, we will take steps to make it known that your actions were conducted in compliance with this policy.