Vulnerability disclosure program (VDP)
A public channel and a working process for vulnerability reports from outside: policy, security.txt, intake, triage and coordinated disclosure.
Programs and assurance
Design, launch and operation of your bug bounty program: policy, scope, reward table, triage and communication with researchers.
Programs and assurance
A bug bounty program is a public promise: report a vulnerability under these rules and you will be treated fairly and paid. Programs fail when the promise is made before the organisation can keep it. Reports pile up unanswered, duplicates and scanner output bury the valid findings, and researchers move on to programs that respond.
We know programs from the side of the researcher, because we hunt in them ourselves. We prepare yours so that it attracts the people you want: a scope that is worth their time, rules that protect them, rewards that match the impact, and answers that arrive when promised.
01Scope
02Approach
Before anything is announced we test the scope ourselves. Issues that any researcher would find in the first week are fixed first, so that rewards are paid for what is hard to find.
Policy, scope and reward table are drafted with your security, legal and finance teams. The safe harbour text follows the wording recognised by the research community.
The program opens to a limited group of invited researchers. Processes are adjusted under a manageable volume of reports.
We triage every report, reproduce it, rate it and pass confirmed findings to your engineers. Researchers receive an answer within the time stated in the policy.
Scope and audience grow when the numbers show that the organisation keeps up: response times held, fixes delivered, budget under control.
03
04
05Standards
How an organisation receives reports and publishes advisories.
ISO/IEC
How a reported vulnerability is investigated and resolved internally.
ISO/IEC
Reference wording of safe harbour for good-faith research.
disclose.io
Format of security.txt.
IETF
Severity score and vector of every finding.
FIRST
06Questions
It depends on where your researchers are, which jurisdictions and payment routes you need, and how much of the operation you want the platform to carry. One of the options is our own platform. We compare it with the others by the same requirements, say so plainly, and take no commission from any other platform.
No. Managing a program and earning rewards from it is a conflict of interest. Our specialists do not submit reports to programs that we operate or have prepared.
If you have not had a penetration test, no. Start with a test and a private program. A public launch on an untested scope pays high rewards for findings that a fixed-price assessment would have delivered.
Every report is reproduced before it is accepted. A report that cannot be reproduced is closed with an explanation, whoever or whatever wrote it. The policy states this, which discourages the submissions in the first place.
08Request
Reference
Keep the reference: we name it in all further communication with you.
We never ask for payment, passwords or remote access in the first reply.