Home / Knowledge hub / Vulnerability disclosure
Knowledge hub
Vulnerability disclosure
Telling an organisation about a flaw, and the policy that makes it safe.
What it means
Vulnerability disclosure is somebody telling an organisation about a flaw in its product, plus the published policy that makes reporting safe.
A workable policy names what is in scope and explains how to report. It promises you will not pursue a good faith test within those limits, and sketches what happens next. NIST SP 800-216 lays out the same shape for federal agencies.
Publishing one costs a page, an inbox and a decision about who answers what arrives in it.
Why it matters
People will find things in your product whether you invite them or not. The only question is whether the finder has an obvious address, or spends a week hunting for one and posts publicly instead.
Safe harbour in writing is what makes a stranger willing to report at all. Without it, silence is their safest option. Buyers notice as well. A missing policy comes up during a security questionnaire, and a page plus an inbox is a small price for hearing bad news early.
How it shows up
Check the basics. A page anybody can find. An address that reaches a person. A scope that says what is off limits, and a promise to acknowledge within a stated time. Then check that somebody reads that inbox.
Decide in advance who triages a report, how fast you reply, and what you do when a finder sets a deadline. Working that out while a stranger waits is how disclosure goes badly. Cyberlop does not run a disclosure programme on your behalf, though it does publish its own policy, covering scope, safe harbour and what to expect. How we handle reports.
Questions people ask
Vulnerability disclosure, answered
What is the difference between a disclosure policy and a bug bounty?
A disclosure policy is the channel and the legal comfort. A bug bounty adds money for qualifying reports.
Every bounty programme contains a disclosure policy inside it. The reverse is not true, and you should not run a bounty until the policy underneath it works.
Do we have to pay people who report bugs?
No. Plenty of organisations run a disclosure policy with no payment at all, offering acknowledgement and a straight answer instead.
Paying changes the volume and the quality of what arrives, in both directions. Start without it and see what your inbox looks like.
What does safe harbour actually protect?
It is your written promise not to pursue legal action against somebody testing in good faith within the scope you published.
It is not a court ruling and it does not bind anybody else, such as your hosting provider. It is still the sentence that decides whether a stranger writes to you.
What if the finder gives us a deadline?
Take it seriously and reply the same week. Most researchers extend a deadline for a team that answers, explains the fix schedule and keeps in touch.
Silence is what turns a private report into a public post. Agree internally, before this happens, who is allowed to negotiate dates.
Do we need a security.txt file?
It helps. A short file at a predictable path tells a finder where to send a report without hunting through your site.
It costs almost nothing and removes the most common excuse for publishing a flaw rather than reporting it.
Related
Terms that sit next to this one
Bug bounty
Paying outside researchers for vulnerabilities they report responsibly.
CVE
A public reference number for one known flaw in one piece of software.
Vulnerability management
The loop of finding, prioritising, fixing and checking the fix held.
Zero day
A vulnerability exploited before any fix exists.
Found something in Cyberlop itself?
Our policy sets out scope, safe harbour and what to expect, and we would far rather hear from you than read about it later. Get in touch and we will acknowledge it.
Or start with a $199 pilot on one application: thirty days, success criteria agreed before day one, credited against the annual if you convert.