
disclose.io
We're here to make vulnerability disclosure safe, simple, and standardized for everyone.
Let's get started...
I want to accept security reports
Launch a VDP that researchers trust. Policymaker generates everything you need: safe harbor language, security.txt, and disclose.io-compliant policies.
I found a vulnerability
Look up the organization's disclosure program, check their safe harbor status, and get help navigating the process if you need it.
I want to protect researchers
Access model policies, legal frameworks, and safe harbor guidance. Help advance the legal protections security researchers need.
I want to contribute
Join the community, contribute to open resources, or help organizations adopt better disclosure practices.
Frequently asked questions
Got a quick question? Let's get you a quick answer
Why does disclose.io exist?
A couple of talks to get you started...
An intro to disclose.io and hacker safety
caseyjohnellis at HackerCon 2021
Hacking the Law - Are Bug Bounties a True Safe Harbor?
Amit Elazari at BSidesSF 2018
Hacking Policy and Policy Hacking
Amit Elazari at BSidesSF 2023
Leonard Bailey + Casey Ellis + Marten Mickos
Cybertalks 2017
Didn't find what you were looking for?
We're always happy to help answer your questions about vulnerability disclosure.
