Bug bounty program management
Design, launch and operation of your bug bounty program: policy, scope, reward table, triage and communication with researchers.
Programs and assurance
A public channel and a working process for vulnerability reports from outside: policy, security.txt, intake, triage and coordinated disclosure.
Programs and assurance
Sooner or later someone outside the company finds a vulnerability in your product. What happens next depends on whether they can find an address to write to and on whether anyone answers. Where there is no channel, the report goes to a support inbox, to social media or nowhere at all.
A disclosure program is the minimum: a published policy that says how to report and what the reporter may expect, an inbox that is read, and a process that takes a report from receipt to a fix. It pays no rewards and needs no platform. The EU Cyber Resilience Act makes a coordinated disclosure policy mandatory for manufacturers of products with digital elements: reporting of actively exploited vulnerabilities applies from 11 September 2026, the full set of obligations from 11 December 2027.
01Scope
02Approach
We draft the policy with your legal team. The safe harbour wording follows the text that the research community recognises, adapted to your jurisdiction by your lawyers.
The intake channel and security.txt are set up and tested from outside, the way a researcher would find them.
Roles, deadlines and escalation are written down and rehearsed on a test report before the policy is published.
If you wish, we operate the intake: acknowledge, reproduce, rate and hand confirmed reports to your engineers.
03
04
05Standards
How an organisation receives reports and publishes advisories.
ISO/IEC
How a reported vulnerability is investigated and resolved internally.
ISO/IEC
Format of security.txt.
IETF
Reference wording of safe harbour for good-faith research.
disclose.io
Severity score and vector of every finding.
FIRST
06Questions
Do not pay under pressure and do not threaten. Acknowledge receipt, ask for the technical detail and verify the claim. Most unsolicited reports come from researchers acting in good faith, some are automated noise, a few are extortion. We verify the report, assess its severity and help you answer; request it through the form on this site and mention that a report is pending.
A disclosure program receives reports and promises fair treatment. A bug bounty adds payment and thereby invites active searching. The first is a baseline for every company with a product online, the second is a decision about budget and readiness.
It commits you not to pursue people who follow your rules. It does not authorise anything outside those rules and it does not bind third parties or prosecutors. The text is reviewed by your lawyers before publication.
08Request
Reference
Keep the reference: we name it in all further communication with you.
We never ask for payment, passwords or remote access in the first reply.