A Practical Guide to Security Disclosure Policies
A published policy telling security researchers how to report vulnerabilities in your systems.
At a glance
- security.txt a standard file that publishes contact details for reports
- Scope policies state what systems are covered
- Safe harbor policies can clarify that good-faith research will not be pursued
- Response reporters expect acknowledgment and updates
Why it matters
Why it matters: Researchers will find issues regardless, and a clear route gets reports to you instead of to attackers or the press.
Best practice
- Publish a security.txt file
- State scope and expectations clearly
- Acknowledge reports quickly
- Keep reporters updated on fixes
- Track reports through to resolution
Common pitfalls
Watch out for:
- No published contact for reports
- Hostile responses to researchers
- Reports lost in shared inboxes
- Scope that is unclear or absent
When to call in a specialist
Bottom line Bring in help when setting up vulnerability handling.
Where this comes from
- RFC Editor — RFC 9116 A File Format to Aid in Security Vulnerability Disclosure
- National Cyber Security Centre — Vulnerability disclosure toolkit
The figures and practices above come from the sources listed.
Working on something like this?
We take on Web Design & Development work for teams who want it done once, properly. Tell us what you are building and we will tell you honestly whether we are the right studio for it. Start a project.
Where to go next
Spotted something wrong? Report an error on this page. We correct on the page and say what changed.