Skip to content

Create & publish a policy

Policies are created through a guided wizard. This page covers the choices you’ll make.

How the policy’s content is produced:

  • Standard: start from a vetted policy template and fill in your details. The fastest path, and it counts toward your maturity rating’s “standard template” criterion.
  • Customized: start from a template, then edit the content.
  • Custom: supply your own policy content from scratch.

In the wizard you’ll set:

  1. Name and short description.
  2. Point of contact (required): where reports go.
  3. CVD timeline: your coordination target in days (30–180).
  4. Safe harbor: full, partial, or none.
  5. Rewards: bounty, swag, and/or hall of fame.
  6. Scope: the assets the policy covers.
  7. Branding: logo, banner, brand colors (hex), and heading/body fonts.
  8. Attestation: confirm the commitments you’re formally making (see Attestation).

How the published policy is served:

ModeWhat it means
self_hostedHosted by Disclose Bot on a public page; copy its link from the app.
custom_domainServed from a domain you own (e.g. security.example.com).
embeddedDesigned to be embedded on your own site with the policy widget.
platform_hostedHosted on the platform.

Publishing makes the policy live at its public URL and available via the public API. You can unpublish to take it down again. Each policy has a stable shortcode used in its public URL and API lookups.