Disclosure and safe harbor
Policy templates, disclosure timelines, CVE handling, advisory publishing and researcher recognition.
A disclosure program only works if good-faith researchers can be confident they will not be pursued for doing the right thing, and if your organisation can meet the timelines it publishes. This document covers the disclosure side of the platform.
Why publish a disclosure policy
- It gives researchers a safe, structured channel instead of a guess at your security contact.
- It sets expectations on both sides — what is in scope, how quickly you respond, and when a finding may be discussed publicly.
- It creates a record of good-faith handling that is useful in any later conversation about a finding.
- It reduces the chance that a report is published before you have had a chance to fix it.
Policy templates
Rather than drafting from scratch, the platform provides policy templates that cover the common structure:
- Commitment statement — what your organisation undertakes to do with reports.
- Safe harbour language — protection for research conducted in good faith and within scope.
- Scope — assets covered, and how they map to the program's scope definition.
- Rules of engagement — prohibited techniques and data handling expectations.
- Reporting channel — where and how to submit, including encrypted evidence handling.
- Response timelines — acknowledgement, triage decision and remediation communication.
- Disclosure — when and how findings may be published, and by whom.
- Recognition — whether credit, a hall of fame entry or a reward is offered.
Templates are starting points. Your own counsel should review the safe harbour and disclosure clauses before publication.
Disclosure timelines
Timelines are configured per program rather than assumed, and the same clock is visible to the reporter:
- Acknowledgement — receipt confirmation, typically automatic.
- Triage decision — validated, duplicate or out of scope.
- Remediation communication — how and when progress is shared.
- Embargo and publication — the point at which coordinated disclosure becomes a public advisory.
Custom disclosure timelines are Enterprise-tier. Other tiers use the standard coordinated disclosure windows.
CVE handling
Where a finding warrants a CVE identifier:
- Request and tracking are handled in the platform, attached to the finding rather than tracked in a separate spreadsheet.
- Status changes flow back onto the finding record.
- Advisory drafts can be prepared while the identifier request is in progress.
Publishing advisories
Advisories are generated from the finding record, so they contain what the record already holds: affected versions or components, severity, root cause, remediation, and credits. Publishing is a deliberate action by the program owner — nothing is published automatically.
Recognition without payment
Not every program pays, and not every reporter wants money. Recognition options include:
- Hall of fame and leaderboards with a public listing per program.
- Recognition badges attached to a researcher profile.
- Attribution in advisories and release notes for findings that are published.
Recognition is a real incentive in VDP programs; it is the reason many researchers report at all.
Handling reports that fall outside policy
Some reports arrive outside the program: an out-of-scope asset, a technique the policy prohibits, or a good-faith mistake. The workflow records the decision and the reason on the report, so the outcome is explainable and consistently applied.
Availability and limits
- Disclosure policy templating, coordinated disclosure workflow, recognition and advisory publishing are available on all tiers.
- Custom disclosure timelines are Enterprise-tier.
- The platform provides the workflow and the record; the legal position — including safe harbour wording — remains your organisation's responsibility to review and adopt.
Related docs
- Scope and rules of engagement — the policy scope model
- Program models — VDP versus bounty versus expert engagement
- Triage pipeline — where the disclosure decision is recorded
- Identity and access — how reporter identity is protected