FREQUENTLY ASKED
What is the Vulnerability Disclosure Program?
The VDP is an official, structured channel for security researchers to responsibly report vulnerabilities in NTL AP digital assets. It defines what you can test, how to report, and what recognition you receive.
What assets can I test?
Only assets explicitly listed on the Scope page. Do not test anything outside the defined scope. Testing out-of-scope assets voids safe harbor protections.
Can I use automated scanners?
Low-intensity scanning is permitted. Volumetric DoS/rate-limit testing, brute force credential attacks, and automated form submission are not permitted.
How do I submit a report?
Use the Report page to submit your finding with a title, affected asset, vulnerability type, and reproduction steps. Provide sufficient detail for the team to reproduce and verify the issue.
What information should my report include?
Include: the affected URL or endpoint, step-by-step reproduction steps, HTTP request/response samples where applicable, screenshots or video, and your assessment of impact.
What are the response timelines?
Initial acknowledgement within 5 business days. Triage within 14 business days. Resolution target is 90 days for standard findings and 30 days for critical severity.
Will I receive recognition for my finding?
Verified and valid reports from researchers who comply with the program guidelines will be acknowledged in the Hall of Fame. The level of recognition depends on severity and impact.
Is there a monetary bug bounty?
This program currently offers public recognition (Hall of Fame listing) rather than monetary compensation. Reward structures may be updated in future program versions.
Am I protected from legal action?
Yes, if you act in good faith within the defined scope and guidelines, NTL AP will not pursue legal action against you. This safe harbor applies to researchers who comply with the program rules.
Can I publicly disclose the vulnerability?
Please coordinate with us before public disclosure. We request a 90-day embargo period following your initial report. After the issue is resolved or the embargo period expires, coordinated disclosure is welcome.