Coordinated vulnerability reporting
Vulnerability Disclosure Program
A Vulnerability Disclosure Program (VDP) establishes an official channel for coordinated — also known as responsible — disclosure: security researchers report vulnerabilities directly to you, get time to fix them before anything is published, and you avoid being caught unprepared if a vulnerability would otherwise have been found and shared without warning.
The basics
What is a VDP?
A VDP sets out the formal ground rules for how external security researchers get in touch: which systems may be tested, where reports should be sent, and how much time you have to fix a vulnerability before it is disclosed. That gives you a predictable process, rather than relying on each researcher figuring out how to reach you on their own.
Without a VDP, researchers often discover vulnerabilities without knowing how to report them safely — risking that the finding either never reaches you, or is published without coordination. A VDP is relevant for both public authorities and businesses that want an official, secure route for external findings.
The process
The path from finding to fix
-
Policy setup
We draft the disclosure and safe harbor policy together with you, tailored to whether you are a public authority or a business.
-
Publication
The programme is made available so researchers can find and use the secure reporting channel.
-
Intake and triage
Incoming reports are received through the reporting channel and validated, either by you or by our team, depending on the plan.
-
Follow-up
You close the vulnerabilities within the agreed timeframe and can choose to credit the researcher for the finding.
The result
A published disclosure policy and safe harbor statement, a secure reporting channel, and a fixed process for receiving and handling coordinated disclosure.
Can be added as part of a managed plan if you want verification of remediated findings.
Services
What it covers
Disclosure policy
We help formulate a clear policy for what may be tested, how findings are reported, and how much time you have to fix them before coordinated disclosure can be considered.
Secure reporting channel
A clear point of contact, so researchers know exactly where and how to submit a finding — instead of guessing or giving up.
Safe harbor
A legal framework that protects researchers who report in good faith, and protects you from unannounced disclosure.
Managed triage
We can handle the technical validation of incoming reports, so you only see confirmed findings.
Audience
Who is it for?
Public authorities
Citizens and security researchers get an official, safe route to flag vulnerabilities in public systems.
Businesses with outward-facing systems
Websites, apps and APIs accessible from the outside get a formal channel for external findings instead of guesswork.
Organisations without bug bounty
You get a structured intake channel for voluntary reporting, without having to pay out rewards.
Legal certainty
A safe channel — protected by Safe Harbor
A legal framework that protects researchers who report in good faith, and protects you from unannounced disclosure.
Supports
FAQ
Questions about VDP
Get started with a VDP
Contact us for a no-obligation quote tailored to your needs.