Skip to content
This repository was archived by the owner on Mar 13, 2025. It is now read-only.

Commit 3534ef5

Browse files
committed
update security.md
1 parent 960e0e3 commit 3534ef5

1 file changed

Lines changed: 1 addition & 1 deletion

File tree

SECURITY.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,7 @@ We require that you:
2020

2121
This policy applies to the following systems:
2222

23-
* [`code.gov`](https://code.gov)
23+
* [`code.gov`](https://code.gov) and the following subdomains: `developers.code.gov`, `api.code.gov`
2424
* Non-public data on public third-party services - TTS utilizes a number of third-party services to support its in-public work model. While non-public data published publically on those services is in scope, testing those services is **not** in scope.
2525

2626
**Any services not expressly listed above, such as any connected services, are excluded from scope** and are not authorized for testing. Additionally, vulnerabilities found in non-federal systems from our vendors fall outside of this policy's scope and should be reported directly to the vendor according to their disclosure policy (if any). If you aren't sure whether a system or endpoint is in scope or not, contact us at [`tts-vulnerability-reports@gsa.gov`](mailto:tts-vulnerability-reports@gsa.gov) before starting your research.

0 commit comments

Comments
 (0)