
disclose.io
We're here to make vulnerability disclosure safe, simple, and standardized for everyone.
Let's get started...
I want to accept security reports
Launch a VDP that researchers trust. Policymaker generates everything you need: safe harbor language, security.txt, and disclose.io-compliant policies.
I found a vulnerability
Look up the organization's disclosure program, check their safe harbor status, and get help navigating the process if you need it.
I want to protect researchers
Access model policies, legal frameworks, and safe harbor guidance. Help advance the legal protections security researchers need.
I want to contribute
Join the community, contribute to open resources, or help organizations adopt better disclosure practices.
Frequently asked questions
Got a quick question? Let's get you a quick answer
Why does disclose.io exist?
A couple of talks to get you started...
An intro to disclose.io and hacker safety
caseyjohnellis at HackerCon 2021
Hacking the Law - Are Bug Bounties a True Safe Harbor?
Amit Elazari at BSidesSF 2018
Hacking Policy and Policy Hacking
Amit Elazari at BSidesSF 2023
Leonard Bailey + Casey Ellis + Marten Mickos
Cybertalks 2017
Stay in the loop
Get the latest on vulnerability disclosure policy, safe harbor developments, and community news.
Subscribe to our newsletterDidn't find what you were looking for?
We're always happy to help answer your questions about vulnerability disclosure.
