Skip to content

Briefs overview

A brief is an intake page. It presents your rules and a submission form, and turns incoming reports into vulns in your inbox.

FieldDescription
NameThe brief’s title.
Short descriptionA one-line summary.
DescriptionThe program overview shown to reporters.
Rules of engagementWhat testing is and isn’t allowed.
Submission policyGuidance on how to write a good report.
FAQCommon questions and answers.
AssetsThe in-scope assets (domains, wildcards, URLs, and more) for this brief.
PoliciesLinked policies shown alongside the brief.
BrandingLogo, banner, colors, and fonts for the public page.

A published brief page presents the program information, rules of engagement, FAQ, in-scope assets, linked policies, and a submission form where a reporter enters a title, description, optional contact email, and the affected assets.

When a report is submitted, it becomes a vuln in your organization’s inbox; see Submissions & the API.

Like policies, briefs are drafts until published. Only published briefs are reachable publicly. See Create & publish.