Skip to content

Claim your organization & publish your policy

You’ve just found your organization listed in a Disclose Bot directory. This walks you through taking ownership of that listing and keeping your vulnerability disclosure policy details up to date.

There are two parts:

  1. Claim your organization: prove you own it and get owner access.
  2. Create or update your policy: set your disclosure details and publish them.
  • An email address at your organization’s domain (a work email, not a personal Gmail/Outlook address).
  • The ability to add a DNS record to one of your organization’s domains, or someone on your team who can.

On your organization’s page in the directory, click the Claim This Organization! button.

You’ll land on a sign-in page. Enter your work email address and click Send link.

  • You don’t need a password; we email you a one-time sign-in link.
  • If you’ve never signed in before, an account is created for you automatically.

Open the email and click the sign-in link. That signs you in and starts your claim.

After signing in you’ll arrive at the Welcome screen, which shows that you’re claiming your organization along with a status badge.

To prove ownership, verify one of your organization’s domains:

  1. Choose (or enter) a domain associated with your organization and click Verify.
  2. The page shows a TXT record to add to that domain’s DNS. It looks like disclosebot-verify=<a long unique token>. Copy the exact value shown.
  3. Add that TXT record in your DNS provider.
  4. Come back and click Check now.

Once your domain is verified, your claim moves to Pending Review. We review the claim and approve it. When it’s approved:

  • You’re added to the organization as the owner.
  • You’ll see a confirmation that you’ve been added.
  • Click Go to Dashboard to start managing your organization.

The organization is now yours to manage.

Once you’re in the dashboard as owner, you can create your vulnerability disclosure policy or edit an existing one. Publishing a policy is what makes your organization appear in “all organizations” directories and is what drives your maturity rating.

  • In the left sidebar, click Policies.
  • Click Create a policy to start a new one, or the edit (pencil) icon on an existing policy to change it.
  • If you started one earlier, it appears under your drafts with a Resume button.

The editor walks you through these steps. Use Next to advance and Back to return; nothing is public until you publish at the end.

  1. Template: choose a starting template, or start blank.
  2. Content: edit the body text of your policy.
  3. Details: Policy Name (required) and Point of Contact (required, where reports go), plus optional Policy URL, Contact URL, security.txt URL, Hall of Fame URL, short description, and launch date.
  4. Commitments: attest to what your program offers. Each section has an Attest button: Safe Harbor (full / partial / none), Disclosure (whether public disclosure is allowed and your CVD timeline), and Rewards (bounty and/or swag).
  5. Assets: assign which of your assets this policy covers. You can skip this and assign assets later.
  6. Hosting: leave as-is to have Disclose Bot host the policy page, or set a custom domain using the CNAME instructions shown.
  7. Branding: optional logo, banner, colors, and fonts.
  8. Review: check everything, use Preview to see the public page, then click Create Policy (or Update Policy when editing).

For more on the wizard and hosting modes, see Create & publish a policy.

After you create or update the policy, you’ll see a success screen with a status pill reading Draft.

  • Click Publish. The pill flips to Published and your policy is live at its public URL. (One click, no extra confirmation.)
  • From the same screen you can View Policy, Download PDF, Copy HTML, or grab an embed widget snippet.
  • You can Unpublish later from the policy’s view panel if you need to take it offline.
  • Appearing in the directory: publishing at least one policy makes your organization eligible to show in “all organizations” directories (it also needs to be active and listable).
  • Your maturity rating: this reflects the fields you set. It’s produced by an analysis step that runs against your published policy, so it may update on a short delay rather than the instant you click Publish.
GoalWhereAction
Start a claimYour org’s directory pageClaim This Organization!
Sign inSign-in page (email only)Send link
Prove ownershipWelcome screenVerify → add DNS TXT → Check now
Get owner accessAfter approvalGo to Dashboard
Edit policyDashboard → PoliciesCreate a policy / edit
Go liveSuccess screenCreate/Update PolicyPublish