# disclose.io URL: https://disclose.io/ Description: The open, vendor-neutral infrastructure that powers vulnerability disclosure and security reporting. Safe, simple, and standardized for everyone. -------------------------------------------------------------------------------- ## Contact Us URL: https://disclose.io/contact/ Description: Got questions, suggestions, or want to start a disclose.io project? We’d love to hear from you! Reach out to us at hello@disclose.io. You can also say hello over at the disclose.io Community Discourse: contributors to disclose.io as well as many from the finder, builder, CERT, and facilitator communities are there. -------------------------------------------------------------------------------- ## A brief history of vulnerability disclosure URL: https://disclose.io/history/ Description: Major events in the standardization of vulnerability reporting and disclosure It’s easy to look at the steadily improving relationship between hackers and companies and presume that it has always been this way, but that is far from the truth. This timeline captures some of the major events in the standardization of vulnerability reporting and disclosure, as well as the origins of The disclose.io Project. Got a suggestion for this timeline? Send a pull request! -------------------------------------------------------------------------------- ## Bug Bounty Platforms URL: https://disclose.io/platforms/ Description: A community-powered collection of all known bug bounty platforms, vulnerability disclosure platforms, and crowdsourced security platforms. (content lives at external/bug-bounty-platforms/README.md) -------------------------------------------------------------------------------- ## Security URL: https://disclose.io/security/ Description: disclose.io's own vulnerability disclosure policy, report issues to security@disclose.io. About this policy disclose.io operates under its own framework. The policy below is an instance of the canonical VDP with Coordinated Disclosure Window from dioterms, with our organization and reporting channel filled in. Introduction disclose.io welcomes feedback from security researchers and the general public to help improve our security. If you believe you have discovered a vulnerability, privacy issue, exposed data, or other security issues in any of our assets, we want to hear from you. This policy outlines steps for reporting vulnerabilities to us, what we expect, what you can expect from us. Systems in Scope This policy applies to any digital assets owned, operated, or maintained by disclose.io. Out of Scope Assets or other equipment not owned by parties participating in this policy. Vulnerabilities discovered or suspected in out-of-scope systems should be reported to the appropriate vendor or applicable authority. Our Commitments When working with us, according to this policy, you can expect us to: Respond to your report promptly, and work with you to understand and validate your report; Strive to keep you informed about the progress of a vulnerability as it is processed; Work to remediate discovered vulnerabilities in a timely manner, within our operational constraints; and Extend Safe Harbor for your vulnerability research that is related to this policy. Note that disclose.io does not maintain a Hall of Fame or offer financial compensation for vulnerability reports. Our Expectations In participating in our vulnerability disclosure program in good faith, we ask that you: Play by the rules, including following this policy and any other relevant agreements. If there is any inconsistency between this policy and any other applicable terms, the terms of this policy will prevail; Report any vulnerability you’ve discovered promptly; Avoid violating the privacy of others, disrupting our systems, destroying data, and/or harming user experience; Use only the Official Channels to discuss vulnerability information with us; Provide us a reasonable amount of time (at least 90 days from the initial report) to resolve the issue before you disclose it publicly; Perform testing only on in-scope systems, and respect systems and activities which are out-of-scope; If a vulnerability provides unintended access to data: Limit the amount of data you access to the minimum required for effectively demonstrating a Proof of Concept; and cease testing and submit a report immediately if you encounter any user data during testing, such as Personally Identifiable Information (PII), Personal Healthcare Information (PHI), credit card data, or proprietary information; You should only interact with test accounts you own or with explicit permission from the account holder; and Do not engage in extortion. Official Channels Please report security issues via security@disclose.io, providing all relevant information. The more details you provide, the easier it will be for us to triage and fix the issue. Safe Harbor When conducting vulnerability research, according to this policy, we consider this research conducted under this policy to be: Authorized concerning any applicable anti-hacking laws, and we will not initiate or support legal action against you for accidental, good-faith violations of this policy; Authorized concerning any relevant anti-circumvention laws, and we will not bring a claim against you for circumvention of technology controls; Exempt from restrictions in our Terms of Service (TOS) and/or Acceptable Usage Policy (AUP) that would interfere with conducting security research, and we waive those restrictions on a limited basis; and Lawful, helpful to the overall security of the Internet, and conducted in good faith. You are expected, as always, to comply with all applicable laws. If legal action is initiated by a third party against you and you have complied with this policy, we will take steps to make it known that your actions were conducted in compliance with this policy. If at any time you have concerns or are uncertain whether your security research is consistent with this policy, please submit a report through one of our Official Channels before going any further. Note that the Safe Harbor applies only to legal claims under the control of the organization participating in this policy, and that the policy does not bind independent third parties. -------------------------------------------------------------------------------- ## Thanks URL: https://disclose.io/thanks/ Description: We've received your message Thanks! We’ve received your message and will respond as soon as possible. In the meantime, why not sign up and say hello over at The disclose.io Discourse? Many of the contributors to disclose.io as well as many from the finder, defender, and facilitator communities are there - It’s another great place to ask questions, get assistance, and contribute back! -------------------------------------------------------------------------------- ## Research Threats URL: https://disclose.io/threats/ Description: An ongoing archive of legal threats made against security researchers engaged in good-faith vulnerability disclosure. (content lives at external/research-threats/README.md) -------------------------------------------------------------------------------- ## Tools URL: https://disclose.io/tools/ Description: Free, open-source tools from the disclose.io project, for organizations launching a VDP, for researchers finding the right contact, and for everyone working to make vulnerability disclosure simpler. TLDR: disclose.io maintains four free, open-source tools that cover the full disclosure lifecycle: Policymaker generates VDP policy text from canonical templates, Directory and Lookup help anyone find the right disclosure contact for any asset, and Vault cryptographically enforces disclosure deadlines so a committed timeline cannot be reversed. The disclose.io project ships four tools, each free, each open-source, each addressing a specific friction in the vulnerability disclosure pipeline. Policymaker policymaker.disclose.io: Interactive policy generator Generates a customized vulnerability disclosure policy (VDP) for any organization using the canonical legal terms from the disclose.io Framework. Pick a maturity level, fill in the organization name and contact channel, and walk away with safe-harbor language, a security.txt file, and a complete disclose.io-compliant policy. Directory directory.disclose.io: The open VDP and bug bounty programs database Browse every known vulnerability disclosure and bug bounty program. Each entry includes the organization, in-scope assets, policy URL, and any safe-harbor language. Open-source, community-curated, and the data source behind the Lookup attribution tool. Lookup lookup.disclose.io: Security contact attribution Turn any input, domain, IP, URL, email, ASN, npm package, mobile app, hardware product, free-text company name, into the right disclosure contact. The tool chains 11 attribution strategies (security.txt, the Directory, WHOIS, DNS SOA, common security@ aliases, bug bounty platform records, and more) and returns the highest-confidence contact with provenance. Available as a web UI, HTTP API, and MCP server. Vault vault.disclose.io: Cryptographically enforced disclosure deadlines A dead-man’s-switch for vulnerability disclosure. A researcher commits a disclosure with a future publication date; the disclosure is encrypted with a timelock that cannot be bypassed, even by the operators of the vault. On expiry, the disclosure becomes publicly readable, regardless of what happens to anyone involved. Browser extension Chrome extension (also referenced as the Disclose extension) Surfaces the disclose.io directory’s VDP posture for any site you visit, see at a glance whether the organization has a published VDP, what their safe-harbor language is, and where to report a vulnerability. Browse the source Every tool is open-source under the github.com/disclose organization. Contributions, issue reports, and policy improvements all welcome. -------------------------------------------------------------------------------- ## The disclose.io Universe URL: https://disclose.io/universe/ Description: The open standard for safe harbor vulnerability disclosure, and the ecosystem that makes it real. The disclose.io project is the open-source layer between raw standards (ISO 29147, CISA CVD) and commercial platforms, a vendor-neutral, practitioner-first playbook for coordinated vulnerability disclosure. It’s the open infrastructure that powers vulnerability disclosure and security reporting, Internet-wide. Below is the full ecosystem. Every component answers a real question someone asks when they hit the VDP wall. The ecosystem, organised around the DIOstatus maturity scale. Core disclose.io: the framework, docs, and project home directory.disclose.io: the open system of record for every known VDP and bug bounty program disclose.io/programs: curated programs with safe harbor language disclose.io/platforms: bug bounty platforms supporting safe harbor disclose.io/threats: the public archive of legal threats to security researchers disclose.io/history: 20+ years of coordinated disclosure Tools lookup.disclose.io: vendor → security contact, program, and safe harbor status policymaker.disclose.io: guided VDP policy, security.txt, and DNS Security TXT generator vault.disclose.io: cryptographically-enforced coordinated disclosure with deadline enforcement dnssecuritytxt.org: DNS-based security contact discovery Community community.disclose.io: the forum blog.disclose.io: PolicyPulse and commentary (“Running With Scissors”) dates.disclose.io: the shared disclosure calendar (subscribable ICS) Open source dioterms: CC0, lawyer-reviewed safe harbor policy templates diodb: legacy open dataset (superseded by directory.disclose.io as the system of record) policymaker.disclose.io: guided VDP policy generator Legal backstop SRLDF: Security Research Legal Defense Fund Contribute, ask questions, or start a program: hello@disclose.io. -------------------------------------------------------------------------------- ## What is disclose.io URL: https://disclose.io/docs/what-is-disclose.io/ Description: The open, vendor-neutral infrastructure that powers vulnerability disclosure and security reporting. disclose.io is the open, vendor-neutral infrastructure that powers vulnerability disclosure and security reporting. We make it safe, simple, and standardized for everyone. We didn’t join this movement. We started it. disclose.io is the vendor-neutral home for safe harbor, and we publish the free, lawyer-reviewed policy language (dioterms, CC0) the ecosystem runs on. One mission, many tools Open, vendor-neutral properties, each answering a real question: Standards: dioterms (safe-harbor language) and dnssecuritytxt (contacts at the DNS layer). Tools: policymaker (draft a policy), lookup (find who to report to), and vault (coordinate disclosure). Data: directory.disclose.io, the open system of record for every program. Record and commons: /threats, community.disclose.io, and the weekly PolicyPulse. Powered by experts Open-source and expert-maintained, disclose.io provides: Free policies, tools, contact lists, and data; A maturity model that recognizes every level of adoption; and Help for researchers and anyone reporting a security issue. -------------------------------------------------------------------------------- ## Vision and Mission URL: https://disclose.io/docs/vision-and-mission/ Description: Make vulnerability disclosure safe, simple, and standardized for everyone. Mission Make vulnerability disclosure safe, simple, and standardized for everyone. We’re the open, vendor-neutral infrastructure that powers disclosure and security reporting. Vision Every organization welcomes good-faith security research under safe harbor, and no researcher risks legal harm for helping. Our shorthand: a healthy Internet Immune System, or “Neighborhood Watch for the Internet.” -------------------------------------------------------------------------------- ## Design Strategy URL: https://disclose.io/docs/design-strategy/ Description: Our design principles for making secure easy and insecure obvious. Vulnerability reporting is tricky by nature - Every security issue is a snowflake, and the laws, languages, and people involved are unique every single time. To compensate for this and help to make secure easy, and insecure (or bad practice) obvious, disclose.io focusses on these design principles: Legal completeness Simplicity Accessibility Universally recognizable Be useful & safe for security researchers while keeping legal teams happy. Help set clear expectations for security researchers & program owners alike. Easy to understand and hard to misinterpret, for as many people as possible. The Green Padlock for Vulnerability Disclosure. -------------------------------------------------------------------------------- ## Key Objectives URL: https://disclose.io/docs/key-objectives/ Description: The key objectives driving the disclose.io project. Key objectives Create a vibrant community that blends security researchers, policymakers, lawyers, and technology vendors to foster collaboration, and creates high-quality tools and data that support a virtuous cycle. Help organizations promote adoption and excellence to their customers, industry peers, and the security community. Maintain a maturity model and drive a race to the top in disclosure practice. Be the open system of record for every program’s disclosure status, and let anyone look one up or update it. Drive the state of the art in thinking around legal risks faced for security researchers and the steps organizations can take to reduce them. Make tools and techniques freely available to technology vendors to ease the socialization and adoption of VDP. -------------------------------------------------------------------------------- ## For Finders and Hackers URL: https://disclose.io/docs/for-finders-and-hackers/ Description: How disclose.io helps security researchers and finders. As a finder… …who has discovered a security issue, I need help to understand where I should report my findings in a way that balances my own legal safety with my confidence in the issue actually being addressed. …who is a part of the security community, I want to help my peers solve these problems in the same way I want them to be solved for myself. As a security researcher… …who wants to conduct research, I need to know where I can apply my proactive security research skills without fear of legal recourse. …who has discovered a security issue, I need help to understand where I should report the issue, and whether or not I can feel safe doing so. …who is looking for organizations who value my skills and help, I want to be able to find them and be confident that what they tell me is an accurate reflection of their position as an organization. -------------------------------------------------------------------------------- ## For Organizations and Legal Teams URL: https://disclose.io/docs/for-organizations-and-legal-teams/ Description: How disclose.io helps organizations and their legal teams. As an organization… …who is considering starting a VDP, I want confidence in the fact that this is best practice, and not an overly aggressive risk. …who is running a VDP, I want to be able to clearly show my security maturity to my customers, competitors, and any others interested to know. …who is pursuing security maturity, I need a reference to point to in order to explain and validate what progressive security maturity means to an organization like mine. As a legal team… …who has never considered the idea of inviting hacker input before, we need to understand where successful precedent exists around how to structure terms and conditions. …who is seeking to improve the simplicity and utility of VDP language, we want to be able to refer to the consensus of experts to support our point of view. …who is time poor, we want access to free policy boilerplates that have the power of market and legal consensus behind them. How disclose.io can help Note: While this project engages the legal opinion of many, it does not constitute legal advice. Please consult your legal counsel for the specific suitability of the disclose.io terms in your organization. Whether you’re starting from scratch or updating an existing policy, choose the legal terms that best fit your vulnerability disclosure program (VDP) or bug bounty program (BBP). Publish your new policy, or add the safe harbor terms to your existing VDP or BBP policy. Submit a pull request to add your program to the open-source disclose.io program database. The diodb maintainers will confirm details, validate your disclose.io status, and merge your request. Select the appropriate disclose.io Seal based on your Disclose.io Status. Add the seal to your security page, vulnerability policy or reporting page, checkout page, and whatever else you like and let the world know you’re joining the mission! -------------------------------------------------------------------------------- ## Contributors URL: https://disclose.io/docs/open-source-contributors/ Description: The people behind disclose.io, legends, maintainers, and open-source contributors keeping the Internet safer. disclose.io is open-source, not-for-profit, and volunteer-run. Diversity is what powers our mission, both today and into the future. Internet superheroes Some of the legends working on disclose.io who eat, sleep, and breathe making the Internet safer. Founding Members Casey Ellis @caseyjohnellis Amit Elazari @amitelazari Chloé Messdaghi @chloemessdaghi Maintainers Jack Cable @cablej Harley Geiger @harleygeiger FJ Fred Jennings esquiring Beau Woods @beauwoods Jeremy Manoto @jmanoto Andrew MacPherson @andrewmohawk sick.codes @sickcodes Contributors Daniel Trauner @dantrauner JE Jen Ellis infosecjen Jason Haddix @jhaddix Lisa @its-a-lisa M Max   Luke Stephens @hakluke J Jonathan   Maeesha Lohani @0ddInput Open-source Contributors Folks who have shipped meaningful commits across the disclose.io GitHub org. Thank you. Michael Skelton @codingo Sajeeb Lohani @prodigysml Nikita Stupin @nikitastupin Jeff Boothby @jeffboothby David Chou @bcdavidchou Luiz K. Monteiro @adiffpirate Abhinav Prasad @abhinavprasad47 Khaled Mohamed @xElkomy Famo @dradford Jericho @attritionorg gi-el @gi-el How you can contribute Here are some of the ways you can contribute back: Keeping diodb up-to-date Help us maintain diodb as the most comprehensive source of truth. Send us changes or additions to VDPs and bug bounty programs via PR to our Github repo. Help us translate policies Is your country or native language missing? Translate the dioterms Core Terms into your local language, or contextualize the safe harbor terms to suit your local laws. Join the community Sign up to The disclose.io Community, introduce yourself, share research, coordinate policy activism and responses, collaborate with other hackers, and help finders connect with security teams. Spread the word Working with an organization that doesn’t have an established VDP or lacks safe harbor provisions? Point them towards the disclose.io website and encourage them to join the movement. -------------------------------------------------------------------------------- ## Project Directory URL: https://disclose.io/docs/project-directory/ Description: The full ecosystem of disclose.io projects, standards, tools, data, and community resources for vulnerability disclosure. disclose.io maintains an ecosystem of open-source projects that work together to make vulnerability disclosure safer and more accessible. Standards provide the legal and policy foundation, tools make adoption easy, data tracks progress across the internet, and community resources connect the people doing the work. Everything below is free, open-source, and community-maintained. Standards and Templates The policy and legal building blocks that underpin everything else. dioterms: VDP Policy Templates The core set of boilerplate vulnerability disclosure policy templates. Available in multiple languages and adapted for specific geographies, verticals, and regulatory frameworks. These templates are what the Policymaker tool generates from. Repository dnssecuritytxt: DNS Security TXT A proposed standard for publishing security contact and vulnerability disclosure information via DNS TXT records, extending the security.txt concept to organizations and assets where web-based paths aren’t available. Repository diostatus: The Maturity Model and Seal A five-level maturity model for vulnerability disclosure programs, from “no contact” to “full safe harbor with coordinated disclosure.” The disclose.io seal provides a recognizable mark indicating an organization’s level of best-practice adoption. See the full maturity model documentation. Repository Tools Free tools that put the standards into practice. Policymaker A multi-lingual, guided VDP policy generator. Answer a few questions about your organization and get a ready-to-publish vulnerability disclosure policy, safe harbor language, and security.txt, all based on the dioterms templates. policymaker.disclose.io | Repository lookup.disclose.io A security attribution and contact lookup tool. Given a domain, IP, package name, or other identifier, find the right place to report a vulnerability, pulling from security.txt, DNS, WHOIS, bug bounty platforms, and the disclose.io database. lookup.disclose.io diosts: Security.txt Scanner A Go-based scanner that validates security.txt files at internet scale. Powers the data behind the disclose.io VDP adoption surveys. Repository Data and Research Tracking adoption, documenting threats, and building the evidence base for policy work. diodb: The VDP/BBP Database The definitive community-powered database of every known vulnerability disclosure program and public bug bounty program, along with their disclose.io maturity status. The most active project in the ecosystem, contributions welcome via pull request. Repository Data survey: retired The legacy data.disclose.io VDP adoption survey surface has been retired. Use the current disclose.io directory, state-of-disclosure snapshot, and ranked-list disclosure audits for active adoption/maturity data. research-threats: Legal Threats Archive A structured archive of legal threats, cease-and-desist letters, and prosecutions targeting good-faith security researchers. Documents the chilling effect and provides evidence for policy advocacy. Repository Community and Content Where the people are. The disclose.io Community A forum for security researchers, program owners, and policy advocates. Get help with disclosure, find security contacts via Hacker Connect, and coordinate on policy responses. community.disclose.io The Blog and PolicyPulse Newsletter News, analysis, and the weekly PolicyPulse newsletter covering cybersecurity policy developments relevant to vulnerability disclosure. blog.disclose.io This Website The documentation site you’re reading now. Also open-source. Repository Get Involved disclose.io is open-source, not-for-profit, and volunteer-run. See Open-source Contributors for ways to help, or Join a Project to get started. -------------------------------------------------------------------------------- ## Join a Project URL: https://disclose.io/docs/join-a-project/ Description: How to get involved with disclose.io projects. If you’d like to work on any of the disclose.io projects and join our community, we’d love your help! Contact us to get started. -------------------------------------------------------------------------------- ## The disclose.io Community URL: https://disclose.io/docs/the-disclose.io-community/ Description: Join our community Discourse forum. Disclose.io Community Our Discourse at https://community.disclose.io is for sharing research, coordinating policy activism and responses, collaborating with other hackers, and helping finders connect with security teams. Sign up and introduce yourself! -------------------------------------------------------------------------------- ## Advocacy and Activism URL: https://disclose.io/docs/advocacy-and-activism/ Description: Public policy work and open letters from disclose.io. advocacy /ˈadvəkəsi/ (noun): public support for or recommendation of a particular cause or policy. activism /ˈaktɪvɪz(ə)m/ (noun): the policy or action of using vigorous campaigning to bring about political or social change. Open Letters and Statements Following is a collection of letters and statements that disclose.io and/or its members have either co-authored or joined as a signatory, in reverse chronological order: Comments on NIST Cyber AI Profile (February 2026): Joint Cybersecurity Coalition and Hacking Policy Council comments on NIST’s Cybersecurity AI Community Profile, recommending lifecycle-based AI risk management and recognition of red teaming and bug bounty programs for AI systems. Comments on EU CRA Delegated Act on Delaying Incident Notifications (December 2025): Joint Cybersecurity Coalition and HPC comments urging the European Commission to make the 72-hour timeframe for mitigation measures more flexible. Letter in Support for Reauthorization of the Cybersecurity Information Sharing Act of 2015 (July 2025): HPC letter to Congress urging reauthorization of CISA 2015 before its expiration. Comments on the Development of an AI Action Plan (March 2025): HPC comments to the White House on AI security testing and vulnerability disclosure as part of the national AI Action Plan. Resource on Vulnerability Management under the EU Cyber Resilience Act (October 2024): HPC guidance on vulnerability management obligations under the EU CRA framework. Comments to CISA on Cyber Incident Reporting for Critical Infrastructure (CIRCIA) (July 2024): HPC comments on how incident reporting requirements interact with security research and vulnerability disclosure. Reply Comments for DMCA Section 1201 Exemption for Generative AI Research (March 2024): HPC reply comments in the Ninth Triennial Proceeding. The Copyright Office subsequently clarified that prompt injection, jailbreaking, and rate limit bypass do not violate DMCA Section 1201. Joint Letter of Experts on CRA and Vulnerability Disclosure (October 2023): Open letter signed by 50+ cybersecurity experts opposing the EU CRA’s Article 11 requirement for 24-hour disclosure of actively exploited unpatched vulnerabilities. AI Red Teaming: Recommendations for Legal Clarity and Liability Protections (December 2023): HPC recommendations establishing that AI red teaming needs legal safe harbors similar to those for traditional security research. Position Statement on State Charging Policies for Security Researchers (August 2023): HPC statement addressing the risk that state prosecutors can pursue CFAA-style cases that federal prosecutors would decline, calling for reform of state-level charging policies. Joint Letter to OFAC re Vulnerability Guidance (May 2023): HPC letter requesting OFAC clarify that receiving vulnerability disclosures from individuals in sanctioned countries is not restricted under sanctions. Security Researcher Statement on the DMCA (June 2021): EFF statement on DMCA exemptions for good-faith security research, co-signed by disclose.io and others. Calling for Cybersecurity in Critical Infrastructure Modernization (May 2021): Coalition letter urging Congress and the Biden Administration to integrate cybersecurity requirements into infrastructure modernization legislation. An Open Letter on Election Security (November 2020): Open letter alongside the EFF, Bugcrowd, the Centre for Democracy and Technology, Verified Voting, and others. Open Letter to Columbus City Attorney Zach Klein: Regarding the prosecution of a security researcher who reported vulnerabilities in city election systems. Response to Voatz: Addressing Voatz’s claims about security researchers who identified vulnerabilities in their mobile voting application. Hacking Policy Council In April 2023, disclose.io members helped launch the Hacking Policy Council (HPC) at the Center for Cybersecurity Policy and Law. The HPC brings together Bugcrowd, Google, HackerOne, Intel, Intigriti, LutaSecurity, Microsoft, and Trend Micro to advance policy protections for good-faith security research. Since its founding, the HPC has published 35+ formal comments, position statements, and policy resources spanning NIST, CISA, the U.S. Copyright Office, UK DSIT, the EU Cyber Resilience Act, the Pall Mall Process, and more. The complete archive is available on the Hacking Policy Council page. -------------------------------------------------------------------------------- ## Press Mentions URL: https://disclose.io/docs/press-mentions/ Description: Media coverage and press mentions of disclose.io. Date Type Publication Author Title 1/2026 Reference IoT Security Foundation Copper Horse / IoTSF The State of VDP Usage in Global Consumer IoT in 2025 3/6/2025 Partner Reference Intigriti Intigriti Safe harbor legal framework for ethical hackers officially launches in Belgium 12/11/2023 Press Dark Reading Staff Safe Harbor Programs: Ensuring the Bounty Isn’t on White Hat Hackers’ Heads 12/13/2023 Op-Ed Dark Reading Casey Ellis The Unlikely Romance of Hackers and Government Suitors 4/2023 Press TechTarget Staff Hacking Policy Council launches, aims to improve bug disclosure 4/2023 Reference Center for Cybersecurity Policy Staff Center for Cybersecurity Policy and Law Launches Initiatives To Support Detection and Remediation of Security Vulnerabilities 4/5/2023 Academic Duke FinReg Blog Staff Security Researchers Battle Against The DMCA 2023 Podcast Delinea Joseph Carson 401 Access Denied Ep 94: Crowdsourced Security & Vulnerability Disclosure with Casey Ellis 2022 Press The Daily Swig Staff HackerOne encourages customers to adopt standard policy to protect hackers from legal problems Summer 2022 Reference NASS / Ingalls Ingalls Information Security disclose.io Managing Disclosure of Vulnerabilities and Risk 6/2021 Signatory EFF EFF Standing With Security Researchers Against Misuse of the DMCA 6/2021 Press SecurityWeek Staff Cybersecurity Companies Join Forces Against Controversial DMCA Section 6/2021 Press The Daily Swig Staff Security organizations join forces with EFF to lobby for DMCA reform 6/23/2021 Partner Reference Bishop Fox Bishop Fox Our Position on the Digital Millennium Copyright Act (DMCA) 6/23/2021 Partner Reference Rapid7 Rapid7 Rapid7 Joins Statement On DMCA Lawsuits Against Security Tools 6/23/2021 Partner Reference NCC Group NCC Group NCC Group co-signs the EFF’s Statement on DMCA Use Against Security Researchers 3/9/2021 Reference NASS NASS Coordinated Vulnerability Disclosure Issue Briefing 1/21/2021 Press Dataversity Casey Ellis Cyberwarfare, Ethical Hacking, and Ransomware: 2021 Predictions 11/17/2020 Partner Reference Center for Democracy and Technology William T. Adler CDT Joins EFF, Other Experts in Open Letter on Election Security 11/16/2020 Reference EFF EFF Elections Are Partisan Affairs. Election Security Isn’t. 11/7/2020 Partner Reference AWS AWS Disclose.io adoption 10/28/2020 Press Threatpost Lindsey O’Donnell How the Pandemic is Reshaping the Bug-Bounty Landscape 10/23/2020 Press VentureBeat Chris O’Brien How ethical hackers are trying to protect the 2020 U.S. elections 9/2020 Reference CISA CISA BOD 20-01: Develop and Publish a Vulnerability Disclosure Policy 2020 Press The Hill Staff Voting equipment companies throw weight behind enhanced disclosures 2020 Press CyberScoop Staff Top voting vendor ES&S publishes vulnerability disclosure policy 2020-2025 Reference IoT Security Foundation IoT Security Foundation The State of Vulnerability Disclosure Policy Usage in Global Consumer IoT (Annual Reports) 7/11/2019 Partner Reference Kaspersky Kaspersky Team Building trust together with Disclose.io 5/31/2019 Press TechCrunch Zack Whittaker Security startup Bugcrowd on crowdsourcing bug bounties 5/2/2019 Partner Reference Bugcrowd Jason Haddix Disclose.io - The Movement Marches Forward 1/29/2019 Press Total Security Advisor Staff Open Source Collaborative Hopes to Make Reporting Security Bugs Safer for All 12/3/2018 Partner Reference Bugcrowd Jason Haddix Protecting Hackers (by default) with Disclose.io 11/6/2018 Press The Daily Swig Staff Open source Disclose.io framework bridges legal gap in bug reporting 9/5/2018 Press Threatpost Tom Spring The Vulnerability Disclosure Process: Still Broken 8/9/2018 Press CSO Online J.M. Porup Bug bounties offer legal safe harbor. Right? Right? 8/7/2018 Press AB Open Gareth Halfacree Disclose.io Aims to Protect Security Researchers 8/6/2018 Press Help Net Security Staff Bugcrowd launches Disclose.io to provide a safe harbor for white hat hackers 8/3/2018 Press Washington Post Derek Hawkins The Cybersecurity 202: The law doesn’t protect ethical hackers. This new project could help close that gap. 8/3/2018 Press CyberScoop Zaid Shoorbajee Open source project looks to give legal safe harbor for ethical hackers 8/2/2018 Press ZDNet Charlie Osborne Disclose.io: A safe harbor for hackers disclosing security vulnerabilities 8/2/2018 Press Linux.com Ars Technica New Open Source Effort: Legal Code to Make Reporting Security Bugs Safer 8/2/2018 Press TechTarget Staff Disclose.io launches vulnerability disclosure ‘safe harbor’ 8/2/2018 Podcast TechTarget Staff Risk & Repeat: Can Disclose.io help protect vulnerability researchers? 8/2/2018 Partner Reference Bugcrowd Amit Elazari Standardizing Legal Safe Harbor for Security Research 8/2/2018 Podcast Threatpost Staff Bugcrowd Founder on Printer Bugs, IoT Bounty Hunting, and New VDP Project 8/2/2018 Press Release GlobeNewswire Bugcrowd Bugcrowd Launches Disclose.io Open-Source Vulnerability Disclosure Framework - Reference OWASP OWASP Vulnerability Disclosure Cheat Sheet - Reference CERT/CC CERT/CC Guide to Coordinated Vulnerability Disclosure - Policy Templates - Reference MIT Election Lab MIT Coordinated Vulnerability Disclosure Research - Partner Reference HackerOne HackerOne Safe Harbor Overview & FAQ - Partner Reference Bugcrowd Bugcrowd Disclose.io and Safe Harbor - Reference Wikitia Wikitia Disclose.io -------------------------------------------------------------------------------- ## Conference Talks and Videos URL: https://disclose.io/docs/conference-talks-and-videos/ Description: Talks and presentations about disclose.io and vulnerability disclosure. Featured Talks More Videos Hacking Policy and Policy Hacking: Amit Elazari, BSidesSF 2023 The State of Vulnerability Disclosure The State of Bug Bounties & AMA: Casey Ellis, Bugcrowd LevelUp 0x01, 2017 Leonard Bailey + Casey Ellis + Marten Mickos: Cybertalks 2017 Bug Bounty Legal Discussion How bug bounties can impact critical infrastructure: Casey Ellis, Passcode Security of Things Forum, 2016 Vulnerability Disclosure Best Practices How building a better hacker accidentally built a better defender: Casey Ellis, OWASP AppSec California, 2015 The Art & Value of Bug Bounties: Casey Ellis & Keren Elezari, 2015 Safe Harbor for Security Research Policy Panel Discussion Presenting Bugcrowd (Most Innovative Company): Casey Ellis, LAUNCH Silicon Valley, 2013 -------------------------------------------------------------------------------- ## Legal Disclaimer URL: https://disclose.io/docs/legal-disclaimer/ Description: Important legal information about disclose.io. Disclaimer While we’ve engaged the legal opinion of many, this does not constitute legal advice. Please consult your legal counsel for the specific suitability of the disclose.io terms in your organization. -------------------------------------------------------------------------------- ## Who is disclose.io for? URL: https://disclose.io/faqs/who-is-this-for/ Hackers and finders: You want to help but aren’t sure you’re welcome. We help you make safe decisions and reach the right people. Legal teams: Inviting hackers is still novel territory. We make it simple to give consensus-backed advice. Organizations: Vulnerabilities come with innovation. We help you say so, loudly and proudly. Security researchers: You’ve been waiting for the red carpet. We’ll help you find it. -------------------------------------------------------------------------------- ## What is Safe Harbor? URL: https://disclose.io/faqs/safe-harbor/ Most anti-hacking laws pre-date the idea of hacking for good, or the “digital locksmiths” who increasingly shape modern digital safety. Those laws get used to suppress good-faith research and limit bad publicity for vendors. The result is a “chilling effect” that silences the very people the Internet most needs to hear from. If hackers are the Internet’s immune system, the Internet still has an auto-immune problem. Safe Harbor is language added to a policy that lets people acting in good faith, as the recipient defines it, report security issues without fear of legal repercussions. disclose.io helps define, spread, and reward Safe Harbor and other disclosure best practices. -------------------------------------------------------------------------------- ## How do I interact with or contribute to the disclose.io projects? URL: https://disclose.io/faqs/how-to-interact/ Glad you asked! Start or upgrade a vulnerability disclosure program (VDP) with best practices like Safe Harbor and clear disclosure timelines. Join the community and help finders connect with the security teams who need to hear from them. Help keep the directory of VDPs and bug bounty programs accurate and up to date. Improve the dioterms disclosure policy by raising an issue or adding a translation via a pull request. Volunteer as a maintainer on one of our projects. Suggest a new project. -------------------------------------------------------------------------------- ## Is disclose.io a 501(c)(3) nonprofit? URL: https://disclose.io/faqs/not-for-profit/ disclose.io grew out of a merge of earlier standardization efforts by RainForest Puppy, Bugcrowd, CipherLaw, Dropbox, Dr. Amit Elazari, UC Berkeley, the National Telecommunications and Information Administration (NTIA), the US Department of Justice, and others. disclose.io is incorporated as a Delaware nonprofit corporation. We’re completing the steps toward federal 501(c)(3) status, so contributions aren’t tax-deductible yet. -------------------------------------------------------------------------------- ## Is this legal advice? URL: https://disclose.io/faqs/legal-advice/ No. We’ve drawn on many legal opinions, but this isn’t legal advice. Consult your own counsel on whether the disclose.io terms fit your organization. -------------------------------------------------------------------------------- ## Level 0: Not Present URL: https://disclose.io/framework/maturity/level-0/ Description: No findable contact, no policy, no intake method. The organisation has no findable security contact, no security.txt, no disclosed policy, and no public intake method. A researcher discovering a vulnerability has no safe or sanctioned way to report it. From the ecosystem’s perspective, this organisation is effectively invisible, or worse, implicitly hostile to disclosure. What observers see No /.well-known/security.txt No security@ or equivalent mailbox documented publicly No policy page, no disclosure program, no bug bounty listing No response (or a hostile response) to any informal outreach Researcher protection None. A researcher who finds and reports a vulnerability here is relying on goodwill and has no written protections, legal or procedural, whatsoever. Path to Level 1 Publish a security.txt file at /.well-known/security.txt with at minimum a Contact: line pointing to a monitored mailbox or form. That’s it. You’re now Level 1. -------------------------------------------------------------------------------- ## Vulnerability Disclosure Policy URL: https://disclose.io/framework/terms/vdp/ Description: Canonical VDP boilerplate with safe harbor, from the disclose.io framework. Introduction [Organization Name] welcomes feedback from security researchers and the general public to help improve our security. If you believe you have discovered a vulnerability, privacy issue, exposed data, or other security issues in any of our assets, we want to hear from you. This policy outlines steps for reporting vulnerabilities to us, what we expect, what you can expect from us. Systems in Scope This policy applies to any digital assets owned, operated, or maintained by [Organization Name]. Out of Scope Assets or other equipment not owned by parties participating in this policy. Vulnerabilities discovered or suspected in out-of-scope systems should be reported to the appropriate vendor or applicable authority. Our Commitments When working with us, according to this policy, you can expect us to: Respond to your report promptly, and work with you to understand and validate your report; Strive to keep you informed about the progress of a vulnerability as it is processed; Work to remediate discovered vulnerabilities in a timely manner, within our operational constraints; and Extend Safe Harbor for your vulnerability research that is related to this policy. Our Expectations In participating in our vulnerability disclosure program in good faith, we ask that you: Play by the rules, including following this policy and any other relevant agreements. If there is any inconsistency between this policy and any other applicable terms, the terms of this policy will prevail; Report any vulnerability you’ve discovered promptly; Avoid violating the privacy of others, disrupting our systems, destroying data, and/or harming user experience; Use only the Official Channels to discuss vulnerability information with us; Provide us a reasonable amount of time to resolve the issue before you disclose it publicly; Perform testing only on in-scope systems, and respect systems and activities which are out-of-scope; If a vulnerability provides unintended access to data: Limit the amount of data you access to the minimum required for effectively demonstrating a Proof of Concept; and cease testing and submit a report immediately if you encounter any user data during testing, such as Personally Identifiable Information (PII), Personal Healthcare Information (PHI), credit card data, or proprietary information; You should only interact with test accounts you own or with explicit permission from the account holder; and Do not engage in extortion. Official Channels Please report security issues via [reporting channel], providing all relevant information. The more details you provide, the easier it will be for us to triage and fix the issue. Safe Harbor When conducting vulnerability research, according to this policy, we consider this research conducted under this policy to be: Authorized concerning any applicable anti-hacking laws, and we will not initiate or support legal action against you for accidental, good-faith violations of this policy; Authorized concerning any relevant anti-circumvention laws, and we will not bring a claim against you for circumvention of technology controls; Exempt from restrictions in our Terms of Service (TOS) and/or Acceptable Usage Policy (AUP) that would interfere with conducting security research, and we waive those restrictions on a limited basis; and Lawful, helpful to the overall security of the Internet, and conducted in good faith. You are expected, as always, to comply with all applicable laws. If legal action is initiated by a third party against you and you have complied with this policy, we will take steps to make it known that your actions were conducted in compliance with this policy. If at any time you have concerns or are uncertain whether your security research is consistent with this policy, please submit a report through one of our Official Channels before going any further. Note that the Safe Harbor applies only to legal claims under the control of the organization participating in this policy, and that the policy does not bind independent third parties. -------------------------------------------------------------------------------- ## VDP with Coordinated Disclosure Window URL: https://disclose.io/framework/terms/vdp-with-cvd/ Description: Canonical VDP with an explicit coordinated-disclosure timeline. Introduction [Organization Name] welcomes feedback from security researchers and the general public to help improve our security. If you believe you have discovered a vulnerability, privacy issue, exposed data, or other security issues in any of our assets, we want to hear from you. This policy outlines steps for reporting vulnerabilities to us, what we expect, what you can expect from us. Systems in Scope This policy applies to any digital assets owned, operated, or maintained by [Organization Name]. Out of Scope Assets or other equipment not owned by parties participating in this policy. Vulnerabilities discovered or suspected in out-of-scope systems should be reported to the appropriate vendor or applicable authority. Our Commitments When working with us, according to this policy, you can expect us to: Respond to your report promptly, and work with you to understand and validate your report; Strive to keep you informed about the progress of a vulnerability as it is processed; Work to remediate discovered vulnerabilities in a timely manner, within our operational constraints; and Extend Safe Harbor for your vulnerability research that is related to this policy. Our Expectations In participating in our vulnerability disclosure program in good faith, we ask that you: Play by the rules, including following this policy and any other relevant agreements. If there is any inconsistency between this policy and any other applicable terms, the terms of this policy will prevail; Report any vulnerability you’ve discovered promptly; Avoid violating the privacy of others, disrupting our systems, destroying data, and/or harming user experience; Use only the Official Channels to discuss vulnerability information with us; Provide us a reasonable amount of time (at least [number of days] days from the initial report) to resolve the issue before you disclose it publicly; Perform testing only on in-scope systems, and respect systems and activities which are out-of-scope; If a vulnerability provides unintended access to data: Limit the amount of data you access to the minimum required for effectively demonstrating a Proof of Concept; and cease testing and submit a report immediately if you encounter any user data during testing, such as Personally Identifiable Information (PII), Personal Healthcare Information (PHI), credit card data, or proprietary information; You should only interact with test accounts you own or with explicit permission from the account holder; and Do not engage in extortion. Official Channels Please report security issues via [reporting channel], providing all relevant information. The more details you provide, the easier it will be for us to triage and fix the issue. Safe Harbor When conducting vulnerability research, according to this policy, we consider this research conducted under this policy to be: Authorized concerning any applicable anti-hacking laws, and we will not initiate or support legal action against you for accidental, good-faith violations of this policy; Authorized concerning any relevant anti-circumvention laws, and we will not bring a claim against you for circumvention of technology controls; Exempt from restrictions in our Terms of Service (TOS) and/or Acceptable Usage Policy (AUP) that would interfere with conducting security research, and we waive those restrictions on a limited basis; and Lawful, helpful to the overall security of the Internet, and conducted in good faith. You are expected, as always, to comply with all applicable laws. If legal action is initiated by a third party against you and you have complied with this policy, we will take steps to make it known that your actions were conducted in compliance with this policy. If at any time you have concerns or are uncertain whether your security research is consistent with this policy, please submit a report through one of our Official Channels before going any further. Note that the Safe Harbor applies only to legal claims under the control of the organization participating in this policy, and that the policy does not bind independent third parties. -------------------------------------------------------------------------------- ## Level 1: Contact Only URL: https://disclose.io/framework/maturity/level-1/ Description: security.txt published; a researcher can reach someone. No policy yet. The organisation is findable and has a working intake method for security reports. This is typically evidenced by a security.txt file and/or a dedicated security contact (email, form, or URL). The bar is deliberately low, it just means a researcher can reach someone. There is no policy document, no legal commitment, and no defined process. But you exist, and you can be found. What observers see security.txt published at /.well-known/security.txt (RFC 9116) At least one valid Contact: entry (email, URL, or phone) Optionally: Policy:, Encryption:, Acknowledgments:, Hiring:, Preferred-Languages: Researcher protection None in writing. There’s an address to send things to, but no promises about what will happen after you do. Path to Level 2 Publish a VDP document at the Policy: URL listed in your security.txt. At minimum it should describe: What you accept reports about (scope) How to submit a report What researchers can expect back (response cadence, resolution process) See terms/vdp.md for a starting template. -------------------------------------------------------------------------------- ## Safe Harbor URL: https://disclose.io/framework/terms/safe-harbor/ Description: Standalone full safe-harbor clause for attaching to an existing policy. Safe Harbor When conducting vulnerability research, according to this policy, we consider this research conducted under this policy to be: Authorized concerning any applicable anti-hacking laws, and we will not initiate or support legal action against you for accidental, good-faith violations of this policy; Authorized concerning any relevant anti-circumvention laws, and we will not bring a claim against you for circumvention of technology controls; Exempt from restrictions in our Terms of Service (TOS) and/or Acceptable Usage Policy (AUP) that would interfere with conducting security research, and we waive those restrictions on a limited basis; and Lawful, helpful to the overall security of the Internet, and conducted in good faith. You are expected, as always, to comply with all applicable laws. If legal action is initiated by a third party against you and you have complied with this policy, we will take steps to make it known that your actions were conducted in compliance with this policy. If at any time you have concerns or are uncertain whether your security research is consistent with this policy, please submit a report through one of our Official Channels before going any further. Note that the Safe Harbor applies only to legal claims under the control of the organization participating in this policy, and that the policy does not bind independent third parties. -------------------------------------------------------------------------------- ## Simple Safe Harbor URL: https://disclose.io/framework/terms/simple-safe-harbor/ Description: Condensed safe harbor clause for quick adoption. We will consider your security research to be authorized if you make a good faith effort to comply with this policy during your security research. If your activities violate certain restrictions in our Acceptable Use Policy, we will waive those restrictions for the limited purpose of allowing security research. We will not sue you for attempting to circumvent the technological safeguards we have put in place to protect the applications in scope. If a third party takes legal action against you for activities carried out in accordance with this policy, we will make this authorization known. For inadvertent, good-faith violations of this policy, we will not take civil action or file a report with law enforcement. Before doing anything that may be inconsistent with or unaddressed by this policy, please contact us by submitting a report. -------------------------------------------------------------------------------- ## Level 2: Basic VDP URL: https://disclose.io/framework/maturity/level-2/ Description: Public policy document and a real submission channel. No legal protection. There is an actual, publicly accessible document describing how the organisation wants vulnerabilities reported, plus a real communication channel to do it through. The intent is in writing. This is the minimum threshold to be considered a functioning Vulnerability Disclosure Program, but there are no legal protections for the researcher yet. What observers see A public VDP document at a stable URL (often /security/ or /security/policy) Scope language, what’s in, what’s out A concrete submission channel (form, email, platform) Expected response cadence or triage commitments No safe harbor language, OR only passive “we appreciate research” language with no legal commitment Researcher protection None legally. The policy exists as a statement of intent. A researcher doing good-faith testing still has no defence against a CFAA claim, a DMCA claim, or a TOS-based action. Path to Level 3 Add language that promises the organisation will not pursue legal action against researchers who act in good faith and follow the policy. See terms/vdp.md sections on Safe Harbor for baseline language. -------------------------------------------------------------------------------- ## Bug Bounty Program Policy URL: https://disclose.io/framework/terms/bbp/ Description: Canonical BBP boilerplate with rewards structure and safe harbor. Introduction [Organization Name] welcomes feedback from security researchers and the general public to help improve our security. If you believe you have discovered a vulnerability, privacy issue, exposed data, or other security issues in any of our assets, we want to hear from you. This policy outlines steps for reporting vulnerabilities to us, what we expect, what you can expect from us. Systems in Scope [INSERT LIST HERE] This policy applies only to any digital assets owned, operated, or maintained by [Organization Name] for which [Organization Name] can legally authorize security testing. Any assets not listed above are out-of-scope for security testing under this policy. Out of Scope Assets or other equipment not owned by parties participating in this policy or not listed in “Systems In Scope.” Vulnerabilities discovered or suspected in out-of-scope systems should be reported to the appropriate vendor or applicable authority. Rewards Our Commitments When working with us, according to this policy, you can expect us to: Respond to your report promptly, and work with you to understand and validate your report; Strive to keep you informed about the progress of a vulnerability as it is processed; Work to remediate discovered vulnerabilities in a timely manner, within our operational contraints; and Extend Safe Harbor for your vulnerability research that is related to this policy. Our Expectations In participating in our vulnerability disclosure program in good faith, we ask that you: Play by the rules, including following this policy and any other relevant agreements. If there is any inconsistency between this policy and any other applicable terms, the terms of this policy will prevail; Report any vulnerability you’ve discovered promptly; Avoid violating the privacy of others, disrupting our systems, destroying data, and/or harming user experience; Use only the Official Channels to discuss vulnerability information with us; Provide us a reasonable amount of time (at least [number of days] days from the initial report) to resolve the issue before you disclose it publicly; Perform testing only on in-scope systems, and respect systems and activities which are out-of-scope; If a vulnerability provides unintended access to data: Limit the amount of data you access to the minimum required for effectively demonstrating a Proof of Concept; and cease testing and submit a report immediately if you encounter any user data during testing, such as Personally Identifiable Information (PII), Personal Healthcare Information (PHI), credit card data, or proprietary information; You should only interact with test accounts you own or with explicit permission from the account holder; and Do not engage in extortion. Official Channels Please use [reporting channel] to report security issues, providing all relevant information. The more details you provide, the easier it will be for us to triage and fix the issue. Safe Harbor When conducting vulnerability research, according to this policy, we consider this research conducted under this policy to be: Authorized concerning any applicable anti-hacking laws, and we will not initiate or support legal action against you for accidental, good-faith violations of this policy; Authorized concerning any relevant anti-circumvention laws, and we will not bring a claim against you for circumvention of technology controls; Exempt from restrictions in our Terms of Service (TOS) and/or Acceptable Usage Policy (AUP) that would interfere with conducting security research, and we waive those restrictions on a limited basis; and Lawful, helpful to the overall security of the Internet, and conducted in good faith. You are expected, as always, to comply with all applicable laws. If legal action is initiated by a third party against you and you have complied with this policy, we will take steps to make it known that your actions were conducted in compliance with this policy. If at any time you have concerns or are uncertain whether your security research is consistent with this policy, please submit a report through one of our Official Channels before going any further. Note that the Safe Harbor applies only to legal claims under the control of the organization participating in this policy, and that the policy does not bind independent third parties. -------------------------------------------------------------------------------- ## Level 3: Partial Safe Harbor URL: https://disclose.io/framework/maturity/level-3/ Description: A commitment not to pursue legal action. Report safely; test uncertainly. The policy makes a promise not to pursue legal action against researchers acting in good faith. The key word is promissory, language like “we will not pursue” or “we will not take legal action.” This is where researcher protection begins. However, it stops short of explicitly authorising testing, think of it as “you’re safe to report” rather than “you’re safe to test.” The protection is real but incomplete. What observers see Policy language that commits the organisation to non-pursuit for good-faith research Often phrased as “we will not initiate legal action” or “we waive claims against” Scope of the promise is sometimes narrow, only reports through the official channel, only current policy adherents, etc. Testing itself is NOT explicitly authorised Researcher protection Partial. If a researcher reports responsibly and the organisation honors its word, the researcher is protected from action by this organisation. But: Third parties (platforms, law enforcement) are not bound Anti-circumvention laws (DMCA) still apply TOS/AUP violations remain open for action The protection often requires the researcher to already have adhered to the policy, a chicken-and-egg problem if testing itself is the question Path to Level 4 Upgrade the Safe Harbor section to explicitly authorise security testing, and carve out specific exemptions from anti-hacking laws (CFAA, CMA), anti-circumvention laws (DMCA), and the organisation’s own TOS/AUP. See terms/vdp.md Safe Harbor section for canonical language. -------------------------------------------------------------------------------- ## Level 4: Full Safe Harbor URL: https://disclose.io/framework/maturity/level-4/ Description: Explicit testing authorisation and carve-outs from CFAA / DMCA / TOS. The meaningful legal leap. The organisation doesn’t just promise not to sue, it explicitly grants permission to test, and carves out exemptions from the specific laws that typically get researchers in trouble: Anti-hacking laws (CFAA, CMA, or equivalent) Anti-circumvention laws (DMCA, or equivalent) The organisation’s own Terms of Service / AUP Scope, compensation, communication channels, and disclosure process are all clearly defined. A researcher can point to this policy as a legal defence. This is the gold standard for researcher protection. What observers see Policy explicitly authorises security research conducted under the terms as “lawful” and “not an infringement” Specific waivers for CFAA / CMA / anti-hacking law applicability Specific waivers for DMCA / anti-circumvention law applicability Explicit TOS/AUP carve-out for security research activity Clear scope definition, clear communication channels, clear expectations on both sides Often includes third-party-threat language (“if legal action is initiated by a third party against you and you have complied with this policy, we will take steps to make it known…”) Researcher protection Full, for testing. A researcher operating within scope, via the official channels, in good faith, has explicit written authorisation and can point to the policy as a defence in any challenge. What’s still missing at Level 4: public accountability on disclosure timing. The organisation has invited research, but hasn’t committed to a public coordinated-disclosure timeline. Path to Level 5 Add a proactive, public coordinated-disclosure timeline (typically 90 days) with a defined process for extensions. -------------------------------------------------------------------------------- ## Level 5: Full Safe Harbor + CVD URL: https://disclose.io/framework/maturity/level-5/ Description: Level 4 plus a public coordinated-disclosure timeline. Accountable. Everything in Level 4, plus a proactive, public coordinated disclosure timeline, typically 90 days, with a defined process for adjusting it. This creates accountability on the organisation’s side of the equation: researchers know that even if a vendor is slow to act, the vulnerability will eventually see daylight. It transforms the relationship from reactive to collaborative. What observers see Everything in Level 4 A published coordinated-disclosure timeline (commonly 90 days, sometimes 120) A defined extension mechanism, what justifies extending, how it’s negotiated, what the cap is An explicit commitment to public disclosure if the timeline is not met Typically: a CVE issuance process, advisory authoring, researcher credit norms Researcher protection Full, for testing and disclosure. A researcher at Level 5 has: Authorised access for testing (Level 4 properties) A predictable path to public disclosure that doesn’t require consent from the vendor Accountability on both sides: the organisation must actually act, or the vulnerability becomes public Beyond Level 5 diostatus stops at 5 intentionally, the jump from “no program” to Level 5 is already a years-long journey for most organisations. Beyond Level 5, differences become practice- and culture-based rather than policy-based: Proactive outreach to researchers Published payout scales (for BBPs) Public transparency reports Participation in industry-wide CVD coordination (CERT/CC, national CSIRTs, multi-party disclosure) --------------------------------------------------------------------------------