An official State of Ohio government site.

Vulnerability Disclosure Policy

The Ohio Secretary of State emphasizes election security and access to safe, efficient services. Threats to digital infrastructure, including election infrastructure, have increased. The office values the cybersecurity testing community in keeping its systems secure.

If you choose to collaborate with the Ohio Secretary of State’s office by testing for vulnerabilities, please be aware of the office’s policy regarding what systems and testing types are covered, and how to report vulnerabilities.

If you’re familiar with the office’s vulnerability disclosure policy, you may submit a vulnerability report.

Guidelines

The office requires that you:

  • Avoid privacy violations. If you encounter any personally identifiable information (e.g., Social Security numbers, driver license numbers, etc.) or financial information (e.g., credit card or bank account numbers), stop your test and notify the office.

  • Only test as necessary to confirm a vulnerability in systems defined under the policy’s scope. If you've established that a vulnerability exists or encountered sensitive data outlined, stop your test and notify the office.

  • Avoid damaging the system’s user experience, disrupting production systems, destroying data, or manipulating data.

  • Do not compromise or withdraw data, pivot to other systems, or establish command line access or persistence.

  • Use the identified communication channels to report vulnerability information to the office.

  • Keep information about discovered vulnerabilities confidential for at least 120 calendar days after you have notified the office. Review the coordinated disclosure section for details.

The following tests are not allowed:

  • Denial of service (DoS or DDoS).

  • Defacement.

  • Physical testing (e.g., office access, open doors, tailgating).

  • Social engineering (e.g., phishing, vishing).

  • Potentially disruptive test types (e.g., DNS spoofing or DNS tunneling).

  • Functionality bugs, clickjacking, email spoofing, etc. do not fit under the policy’s scope due to their low impact. Testers may report such issues but these problems may not be handled as an issue related to this policy.

Scope

The policy applies to these systems:

  • BoE.ohio.gov

  • MilitaryVotes.ohio.gov

  • OhioBusinessCentral.gov

  • OhioSecretaryOfState.gov

  • OhioSoS.gov

  • SafeAtHomeOhio.gov

  • SoS.state.oh.us

  • Vote.ohio.gov

  • VoteOhio.gov

  • All subdomains of the above systems

The State of Ohio, Ohio.gov, and State.oh.us are outside the scope of this policy. Vulnerabilities found in vendor systems are outside of this policy's scope and should be reported to the vendor. Systems not covered under this policy include (but are not limited to):

  • Voting machines

  • Electronic pollbooks

  • Remote ballot markers

  • County voter registration systems

If you aren't sure whether a website, system, or endpoint fits under the scope of this policy, contact [email protected] before testing.

Authorization

If you make a good faith effort to comply with this policy during your security research, the Ohio Secretary of State’s Office will consider your research authorized under this policy. The office will work with you to understand and resolve any reported vulnerabilities and will not initiate or recommend legal action related to your research when it is conducted in accordance with this policy.

This authorization applies only to the testing of systems defined within the scope section of this policy and only when performed in accordance with the guidelines above. Activities outside of this scope or inconsistent with this policy may be considered unauthorized and could violate state or federal computer-crime law.

You are expected, as always, to comply with all applicable laws.

If, at any time, you have concerns or are uncertain whether your security research is consistent with this policy, please contact us through one of the channels in the reporting a vulnerability section before going any further.

Coordinating Disclosure

The office’s security and IT teams attempt to resolve vulnerabilities in 120 days or less and may disclose the details of those vulnerabilities when they have been resolved.

You may not share your report during this 120-day window. If you believe other agencies may benefit from seeing your report before the vulnerability has been resolved, please communicate this to the Ohio Secretary of State’s office.

Once an identified vulnerability is resolved, or 120 days have passed, the office may coordinate a public advisory with you. Please contact the office prior to releasing any information related to the vulnerability and ensure you are not releasing sensitive information.

Vulnerabilities in the office’s system may be relevant to other state and local governments that use similar technology. The office may share your vulnerability reports with federal, state, local government agencies, and the information-sharing organizations that work with them.

Reporting a Vulnerability

You can submit a vulnerability report using this form.

Reports should include:

  • A description of the location and potential impact of the vulnerability.

  • A detailed description of the steps required to reproduce the vulnerability. Proof of concept scripts, screenshots, and screen recordings are recommended. Please label and protect any exploit code.

  • Any technical information and related materials required to reproduce the issue.

The office will acknowledge your report within seven business days and will work with you to understand the report and validate the vulnerability. The office will attempt to provide you with updates.

The office will notify you when a vulnerability has been resolved and offer the opportunity to test and verify. The coordinated disclosure section describes the office’s commitment to publishing vulnerabilities after reporting. The office does not offer financial compensation for vulnerability testing.