Skip to content

Core concepts

A quick reference to the objects you’ll work with.

Your tenant. Everything (policies, briefs, vulns, assets, directory listings, API keys) belongs to an organization. An organization that has at least one signed-in member is claimed; unclaimed organizations can still appear in directories based on public analysis of their disclosure program.

A published vulnerability disclosure policy: your point of contact, scope, remediation timeline (CVD timeline), and whether you offer safe harbor (full, partial, or none), a bounty, swag, or a hall of fame. A policy is a draft until you publish it. The policy allows you to officially verify: the official safe harbor level, that you allow disclosure and the timeline, and whether you offer rewards or swag. See Policies.

An intake page that presents your rules of engagement, submission guidance, FAQ, in-scope assets, and a submission form. Briefs are how reports get to you. See Briefs.

A vulnerability report submitted through a brief. A vuln carries a title, description, optional reporter email, and any affected assets. It moves through two independent lifecycles:

  • Processing: openclosed (and back via reopen). Triage status.
  • Inbox: dispatchingreceivedstored. How far the report has progressed through intake.

See where submissions go.

Something in your organization’s scope. An asset has a kinddomain, wildcard, url, source_code, or other — and a value (for a domain, the hostname). Assets are attached to policies and briefs either in scope or out of scope, and to vulns to record what was affected.

A curated, public list of organizations and their disclosure programs (for example on disclose.io). Each organization in a directory gets a maturity rating. Your entry in a directory is a directory listing, which you can control. See Directories.