Create & publish a policy
Policies are created through a guided wizard. This page covers the choices you’ll make.
Creation modes
Section titled “Creation modes”How the policy’s content is produced:
- Standard: start from a vetted policy template and fill in your details. The fastest path, and it counts toward your maturity rating’s “standard template” criterion.
- Customized: start from a template, then edit the content.
- Custom: supply your own policy content from scratch.
Key details
Section titled “Key details”In the wizard you’ll set:
- Name and short description.
- Point of contact (required): where reports go.
- CVD timeline: your coordination target in days (30–180).
- Safe harbor:
full,partial, ornone. - Rewards: bounty, swag, and/or hall of fame.
- Scope: the assets the policy covers.
- Branding: logo, banner, brand colors (hex), and heading/body fonts.
- Attestation: confirm the commitments you’re formally making (see Attestation).
Hosting modes
Section titled “Hosting modes”How the published policy is served:
| Mode | What it means |
|---|---|
self_hosted | Hosted by Disclose Bot on a public page; copy its link from the app. |
custom_domain | Served from a domain you own (e.g. security.example.com). |
embedded | Designed to be embedded on your own site with the policy widget. |
platform_hosted | Hosted on the platform. |
Publishing
Section titled “Publishing”Publishing makes the policy live at its public URL and available via the public API. You can unpublish to take it down again. Each policy has a stable shortcode used in its public URL and API lookups.