Independent security researchers and ethical hackers discover vulnerabilities on the internet every day. Without a clear Vulnerability Disclosure Policy (VDP) and a standardized `security.txt` file, researchers who find security flaws in your application have no safe, legal channel to notify your engineering team.
Essential components of an effective VDP
A well-structured disclosure policy sets clear expectations for both the reporting researcher and your internal triage team:
- Safe Harbor commitment: explicitly pledge that researchers acting in good faith according to the policy will not face legal action or law enforcement referrals.
- Clear scope definitions: identify which domains and applications are in scope, and explicitly forbid denial-of-service, social engineering, or customer data destruction.
- Dedicated intake channel: provide a secure email address (e.g., `security@yourcompany.com`) with a published PGP encryption key.
- Realistic response SLAs: commit to acknowledging receipt within 48 to 72 hours and providing ongoing remediation status updates.
Standardizing contact with RFC 9116 security.txt
Publish a `security.txt` file at `/.well-known/security.txt`. This standard machine-readable format allows security researchers, automated tools, and CERT organizations to immediately discover your security contact details and policy links.
A clear Vulnerability Disclosure Policy provides a safe front door for ethical security researchers, preventing quiet vulnerabilities from turning into public zero-day disclosures.