An official website of the United States EMS Compact
Display:
Seal of the Interstate Commission for EMS Personnel Practice

The United States EMS Compact

Interstate Commission for EMS Personnel Practice

Vulnerability Disclosure Policy

How to report a suspected security vulnerability on emscompact.gov, and what to expect from the Commission when you do.

Adopted September 2026

The Interstate Commission for EMS Personnel Practice is committed to the security of this website and of the systems that support the United States EMS Compact. Security researchers and members of the public who believe they have found a security vulnerability on this site are encouraged to report it to us. This policy describes what systems are in scope, how to submit a report, and what you can expect from us.

Authorization and Safe Harbor

If you make a good-faith effort to comply with this policy while researching and reporting a vulnerability, we consider your research authorized. We will work with you to understand and resolve the issue, and the Commission will not recommend or pursue legal action against you for activity that represents a good-faith attempt to follow this policy.

Scope

This policy applies to:

  • www.emscompact.gov, this website, including the Privilege to Practice verification tool.

The following are out of scope:

  • Third-party services this site links to or embeds (for example Google Forms, Google reCAPTCHA, and Mailchimp). Report issues with those services to the vendor.
  • Any system not listed above, including state EMS licensure systems and the National Registry.
  • Denial of service testing, volumetric testing, or any activity that degrades the availability of the site or the verification service.
  • Social engineering (phishing, vishing) of Commission staff, Commissioners, or state offices.
  • Physical attacks against Commission property or personnel.

Guidelines

While researching, we ask that you:

  • Test only within the scope above, and stop testing and submit a report as soon as you confirm a vulnerability or encounter any personal data that is not your own.
  • Do not access, modify, download, or destroy data belonging to others. If personal data is exposed, view the minimum necessary to demonstrate the issue.
  • Do not degrade the service for others, and do not use automated tools at volumes that could do so.
  • Give us a reasonable opportunity to correct the issue before disclosing it publicly. We ask for 90 days from your report.

How to Report

Email your report to with "Vulnerability report" in the subject line. Reports may be submitted anonymously. A useful report includes:

  • The URL or location where the vulnerability was observed.
  • A description of the issue and its potential impact.
  • Steps to reproduce it (proof-of-concept scripts or screenshots help).
  • Any assistive context, such as the browser or tools used.

Please write reports in English if possible.

What to Expect

When you submit a report:

  • We will acknowledge receipt, normally within five business days.
  • We will investigate, keep you informed of our progress as appropriate, and let you know when the issue is resolved.
  • We do not operate a paid bug bounty program.

A machine-readable pointer to this policy is published at /.well-known/security.txt.