<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Framework — Terms on disclose.io</title><link>https://disclose.io/framework/terms/</link><description>Recent content in Framework — Terms on disclose.io</description><generator>Hugo</generator><language>en-us</language><atom:link href="https://disclose.io/framework/terms/index.xml" rel="self" type="application/rss+xml"/><item><title>Vulnerability Disclosure Policy</title><link>https://disclose.io/framework/terms/vdp/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://disclose.io/framework/terms/vdp/</guid><description>Introduction [Organization Name] welcomes feedback from security researchers and the general public to help improve our security. If you believe you have discovered a vulnerability, privacy issue, exposed data, or other security issues in any of our assets, we want to hear from you. This policy outlines steps for reporting vulnerabilities to us, what we expect, what you can expect from us.
Systems in Scope This policy applies to any digital assets owned, operated, or maintained by [Organization Name].</description></item><item><title>VDP with Coordinated Disclosure Window</title><link>https://disclose.io/framework/terms/vdp-with-cvd/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://disclose.io/framework/terms/vdp-with-cvd/</guid><description>Introduction [Organization Name] welcomes feedback from security researchers and the general public to help improve our security. If you believe you have discovered a vulnerability, privacy issue, exposed data, or other security issues in any of our assets, we want to hear from you. This policy outlines steps for reporting vulnerabilities to us, what we expect, what you can expect from us.
Systems in Scope This policy applies to any digital assets owned, operated, or maintained by [Organization Name].</description></item><item><title>Safe Harbor</title><link>https://disclose.io/framework/terms/safe-harbor/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://disclose.io/framework/terms/safe-harbor/</guid><description>Safe Harbor When conducting vulnerability research, according to this policy, we consider this research conducted under this policy to be:
Authorized concerning any applicable anti-hacking laws, and we will not initiate or support legal action against you for accidental, good-faith violations of this policy; Authorized concerning any relevant anti-circumvention laws, and we will not bring a claim against you for circumvention of technology controls; Exempt from restrictions in our Terms of Service (TOS) and/or Acceptable Usage Policy (AUP) that would interfere with conducting security research, and we waive those restrictions on a limited basis; and Lawful, helpful to the overall security of the Internet, and conducted in good faith.</description></item><item><title>Simple Safe Harbor</title><link>https://disclose.io/framework/terms/simple-safe-harbor/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://disclose.io/framework/terms/simple-safe-harbor/</guid><description>We will consider your security research to be authorized if you make a good faith effort to comply with this policy during your security research. If your activities violate certain restrictions in our Acceptable Use Policy, we will waive those restrictions for the limited purpose of allowing security research. We will not sue you for attempting to circumvent the technological safeguards we have put in place to protect the applications in scope.</description></item><item><title>Bug Bounty Program Policy</title><link>https://disclose.io/framework/terms/bbp/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://disclose.io/framework/terms/bbp/</guid><description>Introduction [Organization Name] welcomes feedback from security researchers and the general public to help improve our security. If you believe you have discovered a vulnerability, privacy issue, exposed data, or other security issues in any of our assets, we want to hear from you. This policy outlines steps for reporting vulnerabilities to us, what we expect, what you can expect from us.
Systems in Scope [INSERT LIST HERE]
This policy applies only to any digital assets owned, operated, or maintained by [Organization Name] for which [Organization Name] can legally authorize security testing.</description></item></channel></rss>