Platform

Platform overview How it works Authorization testing Evidence & reports Private scanning Integrations

Solutions

Security agencies Product teams Regulated industries Partner programme

Learn

Blog Knowledge hub Compare

Resources

Pricing Documentation FAQ Security & data What we haven’t proved

Company

About Contact Careers Sign in to the platform Start a $199 pilot

Home / Knowledge hub / Vulnerability disclosure

Knowledge hub

Vulnerability disclosure

Telling an organisation about a flaw, and the policy that makes it safe.

What it means

Vulnerability disclosure is somebody telling an organisation about a flaw in its product, plus the published policy that makes reporting safe.

A workable policy names what is in scope and explains how to report. It promises you will not pursue a good faith test within those limits, and sketches what happens next. NIST SP 800-216 lays out the same shape for federal agencies.

Publishing one costs a page, an inbox and a decision about who answers what arrives in it.

Why it matters

People will find things in your product whether you invite them or not. The only question is whether the finder has an obvious address, or spends a week hunting for one and posts publicly instead.

Safe harbour in writing is what makes a stranger willing to report at all. Without it, silence is their safest option. Buyers notice as well. A missing policy comes up during a security questionnaire, and a page plus an inbox is a small price for hearing bad news early.

How it shows up

Check the basics. A page anybody can find. An address that reaches a person. A scope that says what is off limits, and a promise to acknowledge within a stated time. Then check that somebody reads that inbox.

Decide in advance who triages a report, how fast you reply, and what you do when a finder sets a deadline. Working that out while a stranger waits is how disclosure goes badly. Cyberlop does not run a disclosure programme on your behalf, though it does publish its own policy, covering scope, safe harbour and what to expect. How we handle reports.

Questions people ask

Vulnerability disclosure, answered

What is the difference between a disclosure policy and a bug bounty?

A disclosure policy is the channel and the legal comfort. A bug bounty adds money for qualifying reports.

Every bounty programme contains a disclosure policy inside it. The reverse is not true, and you should not run a bounty until the policy underneath it works.

Do we have to pay people who report bugs?

No. Plenty of organisations run a disclosure policy with no payment at all, offering acknowledgement and a straight answer instead.

Paying changes the volume and the quality of what arrives, in both directions. Start without it and see what your inbox looks like.

What does safe harbour actually protect?

It is your written promise not to pursue legal action against somebody testing in good faith within the scope you published.

It is not a court ruling and it does not bind anybody else, such as your hosting provider. It is still the sentence that decides whether a stranger writes to you.

What if the finder gives us a deadline?

Take it seriously and reply the same week. Most researchers extend a deadline for a team that answers, explains the fix schedule and keeps in touch.

Silence is what turns a private report into a public post. Agree internally, before this happens, who is allowed to negotiate dates.

Do we need a security.txt file?

It helps. A short file at a predictable path tells a finder where to send a report without hunting through your site.

It costs almost nothing and removes the most common excuse for publishing a flaw rather than reporting it.

Found something in Cyberlop itself?

Our policy sets out scope, safe harbour and what to expect, and we would far rather hear from you than read about it later. Get in touch and we will acknowledge it.

Or start with a $199 pilot on one application: thirty days, success criteria agreed before day one, credited against the annual if you convert.