Internet-Draft Machine-Readable CVD Policies September 2026
Behring & Berg Expires 5 March 2027 [Page]
Workgroup:
Network Working Group
Internet-Draft:
draft-behring-cvd-policy-00
Published:
Intended Status:
Standards Track
Expires:
Authors:
B. L. Behring
Skalvar Technologies
M. Berg
Skalvar Technologies

Machine-Readable Coordinated Vulnerability Disclosure Policies

Abstract

This document defines a JSON format for machine-readable Coordinated Vulnerability Disclosure (CVD) policies. It also defines the proposed CVD-Policy field for discovery through security.txt and requests registration of the application/cvd-policy+json media type. The format complements security.txt and human-readable policy documents. A policy does not prove ownership and does not establish legal authorization to test, legal safe harbor, or the safety of an activity.

Status of This Memo

This Internet-Draft is submitted in full conformance with the provisions of BCP 78 and BCP 79.

Internet-Drafts are working documents of the Internet Engineering Task Force (IETF). Note that other groups may also distribute working documents as Internet-Drafts. The list of current Internet-Drafts is at https://datatracker.ietf.org/drafts/current/.

Internet-Drafts are draft documents valid for a maximum of six months and may be updated, replaced, or obsoleted by other documents at any time. It is inappropriate to use Internet-Drafts as reference material or to cite them other than as "work in progress."

This Internet-Draft will expire on 5 March 2027.

Table of Contents