Policies overview
A policy is your published vulnerability disclosure policy: the terms that tell security researchers how to report issues and what to expect in return.
What a policy captures
Section titled “What a policy captures”| Field | Description |
|---|---|
| Name | The policy’s title. |
| Point of contact | Where reports should go (required). |
| Short description | A one-line summary. |
| CVD timeline | Your remediation/coordination target in days (commonly 30, 45, 60, 90, 120, or 180). |
| Safe harbor | The legal protection you offer researchers: full, partial, or none. |
| Bounty / swag / hall of fame | Whether you reward reporters. |
| Public disclosure | Whether issues are disclosed publicly after remediation. |
| Scope | The assets the policy covers. |
| Branding | Logo, banner, colors, and fonts applied to the public page. |
Draft vs. published
Section titled “Draft vs. published”A policy is a draft until you publish it. Only published policies are reachable at their public URL or via the public API. See Create & publish.
What the public page shows
Section titled “What the public page shows”A published policy page renders your policy content along with a summary bar (contact, CVD timeline, safe harbor, rewards, public disclosure) and your branding.
Attestation
Section titled “Attestation”Some commitments (safe harbor, public disclosure, and rewards) can be attested by your organization. The public page shows whether each was attested, with a disclaimer clarifying that un-attested details reflect analysis rather than a formal commitment. Attesting your commitments improves how your program reads to researchers and contributes to your directory maturity rating.