Skip to content

Policies overview

A policy is your published vulnerability disclosure policy: the terms that tell security researchers how to report issues and what to expect in return.

FieldDescription
NameThe policy’s title.
Point of contactWhere reports should go (required).
Short descriptionA one-line summary.
CVD timelineYour remediation/coordination target in days (commonly 30, 45, 60, 90, 120, or 180).
Safe harborThe legal protection you offer researchers: full, partial, or none.
Bounty / swag / hall of fameWhether you reward reporters.
Public disclosureWhether issues are disclosed publicly after remediation.
ScopeThe assets the policy covers.
BrandingLogo, banner, colors, and fonts applied to the public page.

A policy is a draft until you publish it. Only published policies are reachable at their public URL or via the public API. See Create & publish.

A published policy page renders your policy content along with a summary bar (contact, CVD timeline, safe harbor, rewards, public disclosure) and your branding.

Some commitments (safe harbor, public disclosure, and rewards) can be attested by your organization. The public page shows whether each was attested, with a disclaimer clarifying that un-attested details reflect analysis rather than a formal commitment. Attesting your commitments improves how your program reads to researchers and contributes to your directory maturity rating.