Security

At the UL Foundation, we prioritize security, privacy, and transparency in everything we do. This policy outlines how ethical hackers, security researchers, and members of the public can responsibly disclose potential vulnerabilities in our systems.

We recognize that maintaining the trust of our donors, partners, and the communities we serve requires continuous attention to the protection of information and technology resources. While we implement reasonable safeguards designed to protect our systems, we also value the contributions of individuals who responsibly identify and report potential security concerns.

The Responsible Disclosure Policy provides a clear process for reporting suspected vulnerabilities and establishes a framework for communication between security researchers and the UL Foundation. By encouraging responsible reporting, we can evaluate concerns, address potential risks, and strengthen the reliability and security of our digital services.

We appreciate the efforts of those who assist us in improving our security posture and ask that all disclosures be made in a responsible manner that protects the privacy, integrity, and availability of our systems and the individuals who rely on them.

This Responsible Disclosure Policy applies to security concerns identified within UL Foundation digital services and resources. We welcome responsible reports that help us identify potential vulnerabilities and improve the security, reliability, and protection of our systems.

The scope of this policy includes:

  • ulfoundation.org and all associated subdomains
  • Public services, applications, and resources hosted under the UL Foundation name
  • Applications, scripts, or other digital resources officially distributed by the UL Foundation

Reporting a Vulnerability

If you believe you have identified a potential security vulnerability affecting UL Foundation systems or services, we encourage you to report it responsibly so that our team can review and address the concern. Responsible disclosure helps protect our users, partners, and the integrity of our digital resources.

Please report all vulnerabilities to .

We encourage encrypted submissions using our PGP key: https://ulfoundation.org/.well-known/pgp-key.txt

When submitting a report, please provide enough information for our team to understand the issue, evaluate its impact, and begin the appropriate review process.

What to Include

To help us properly evaluate and respond to a reported vulnerability, please include as much relevant information as possible. A complete report allows our team to understand the issue, reproduce the condition, and determine appropriate corrective action.

  • A clear description of the suspected vulnerability and its potential impact
  • The affected website, application, page, or service
  • Detailed steps to reproduce the issue, including any required conditions
  • Screenshots, logs, sample requests, or other supporting evidence when applicable
  • Tools or methods used during testing (if applicable)
  • Your contact information if you would like acknowledgment or follow-up communication

What You Can Expect

We value responsible security research and appreciate individuals who take the time to report potential vulnerabilities. Upon receiving a report, the UL Foundation will review the information provided and determine the appropriate course of action.

  • Acknowledgment of your submission within 5 business days, when sufficient contact information is provided
  • Review of the reported concern to determine its validity, scope, and potential impact
  • Communication regarding the status of the review when appropriate
  • Reasonable efforts to address verified security issues in a timely manner
  • Public acknowledgment in our Hall of Thanks, if permitted and desired by the researcher

We ask that researchers allow reasonable time for review and remediation before publicly disclosing potential vulnerabilities.