Briefs overview
A brief is an intake page. It presents your rules and a submission form, and turns incoming reports into vulns in your inbox.
What a brief captures
Section titled “What a brief captures”| Field | Description |
|---|---|
| Name | The brief’s title. |
| Short description | A one-line summary. |
| Description | The program overview shown to reporters. |
| Rules of engagement | What testing is and isn’t allowed. |
| Submission policy | Guidance on how to write a good report. |
| FAQ | Common questions and answers. |
| Assets | The in-scope assets (domains, wildcards, URLs, and more) for this brief. |
| Policies | Linked policies shown alongside the brief. |
| Branding | Logo, banner, colors, and fonts for the public page. |
What the public page shows
Section titled “What the public page shows”A published brief page presents the program information, rules of engagement, FAQ, in-scope assets, linked policies, and a submission form where a reporter enters a title, description, optional contact email, and the affected assets.
When a report is submitted, it becomes a vuln in your organization’s inbox; see Submissions & the API.
Draft vs. published
Section titled “Draft vs. published”Like policies, briefs are drafts until published. Only published briefs are reachable publicly. See Create & publish.