Skip to content

How to create a hacker-friendly Vulnerability Disclosure Policy (VDP) and security.txt

A complete guide to drafting an effective Vulnerability Disclosure Policy (VDP), setting up security.txt (RFC 9116), and handling external security researcher reports safely.

By BugSnaps Security Research · · 7 min read

Independent security researchers and ethical hackers discover vulnerabilities on the internet every day. Without a clear Vulnerability Disclosure Policy (VDP) and a standardized `security.txt` file, researchers who find security flaws in your application have no safe, legal channel to notify your engineering team.

Essential components of an effective VDP

A well-structured disclosure policy sets clear expectations for both the reporting researcher and your internal triage team:

  • Safe Harbor commitment: explicitly pledge that researchers acting in good faith according to the policy will not face legal action or law enforcement referrals.
  • Clear scope definitions: identify which domains and applications are in scope, and explicitly forbid denial-of-service, social engineering, or customer data destruction.
  • Dedicated intake channel: provide a secure email address (e.g., `security@yourcompany.com`) with a published PGP encryption key.
  • Realistic response SLAs: commit to acknowledging receipt within 48 to 72 hours and providing ongoing remediation status updates.

Standardizing contact with RFC 9116 security.txt

Publish a `security.txt` file at `/.well-known/security.txt`. This standard machine-readable format allows security researchers, automated tools, and CERT organizations to immediately discover your security contact details and policy links.

A clear Vulnerability Disclosure Policy provides a safe front door for ethical security researchers, preventing quiet vulnerabilities from turning into public zero-day disclosures.

Run a real pentest on your app - free.

Sign in, prove you own the domain, and MyPentest maps and tests it. No credit card.