CAIQ v4
Control TVM-08
Extractive Review Standard
How to answer 'Do you operate a Vulnerability Disclosure Policy or Bug Bounty Program?' on a CAIQ
Reviewer Guidance & Pitfalls
State if you have a public security.txt / VDP page with contact info and safe harbor terms. If you run a private/public bug bounty on HackerOne/Bugcrowd, mention it.
Example Answer Passing Enterprise Audit
Compliant Response Template
Yes. We maintain a public Vulnerability Disclosure Policy at [security.txt URL] with documented response SLAs and safe harbor provisions for responsible security researchers.
Filling out a CAIQ or SIG Lite right now?
QuietQuestionnaire automatically drafts answers with citations from your own SOC 2 report, catches contradictions reviewers reject, and locks exports behind cryptographic human sign-off.
Zero spam. 100% confidential. No credit card required.