Directories overview
A directory is a curated, public list of organizations and their disclosure programs, for example the disclose.io directory. It’s how researchers discover who has a program and how mature it is.
What a directory page shows
Section titled “What a directory page shows”A public directory page lists organizations in a searchable, sortable table. For each organization it shows the policy link, the point of contact, and a maturity rating. Visitors can search by name, filter by maturity, and open an organization to see its policies and a detailed assessment.
Maturity ratings
Section titled “Maturity ratings”Each organization is rated against the disclose.io maturity framework:
| Level | Meaning |
|---|---|
| security.txt | An intake method exists. |
| Basic | Public policy + a reporting channel. |
| Partial | Won’t pursue legal action. |
| Full | Explicitly authorises testing + legal exemptions. |
| Full+CVD | Full, plus a proactive coordinated-disclosure timeline. |
The rating is derived from core criteria (published policy, security.txt, contact,
safe harbor, CVD timeline, public disclosure, scope, standard template) and bonus
criteria (bounty, swag, hall of fame).