Answer yes if your organisation has a documented and publicly accessible vulnerability disclosure process that allows external researchers, customers, or other third parties to report suspected security vulnerabilities in your software. Describe this process in the notes section, including expected response times, or upload the policy as evidence.