Vulnerability Disclosure Program (VDP)

Our Commitment to Security

At Vanguard, protecting our clients, systems, and data is a top priority. We recognize the important role that independent security researchers play in helping identify potential security vulnerabilities.

We welcome and encourage the vulnerability disclosure of security issues. This Vulnerability Disclosure Program is intended to provide a clear, secure, and constructive pathway for reporting potential vulnerabilities in our systems, applications, and services.

Program Overview

Before participating in our program, please review the vulnerability disclosure program guidelines to understand the defined scope, program rules, and submission criteria, including the types of submissions that may be considered ineligible or out of scope. This program enables security researchers to responsibly report potential security vulnerabilities while ensuring that:

  • Reports are reviewed and validated in a timely manner
  • Vulnerabilities are remediated appropriately
  • Researchers are protected when acting in good faith

How to Report a Vulnerability

If you believe you have identified a potential security vulnerability, please submit a report including:

  • A detailed description of the issue
  • The affected asset or endpoint
  • Steps to reproduce the issue
  • Supporting materials (e.g., screenshots, logs, proof-of-concept)

Vanguard uses HackerOne to triage and validate responsibly disclosed vulnerability reports. Please submit your report via HackerOne -  https://hackerone.com/vanguard.

Submitting your report via HackerOne will help ensure timely validation.