skip to content

Vulnerability Disclosure Policy

A researcher who cannot find you publishes instead. A security.txt file, a written policy and explicit safe-harbour language make reporting easy and legally safe; a paid bounty is no substitute.

on this pageshow

questions

4

In a vulnerability disclosure policy, what does a safe harbour clause actually promise a researcher?

level: middleimportance: must knowfreq 64%

answer

  1. authorisation, not just forgiveness
  2. removes the unauthorised element
  3. cannot bind third parties
  4. conditioned on described good faith
  5. hedged wording reads as a threat

basics

~10 s

Safe harbour authorises the testing described in the policy and promises the publisher will not pursue legal action over good-faith, in-scope research. It cannot bind prosecutors, other customers, or your own service providers.

solid answer

~50 s

A safe-harbour clause does three things. First, it **authorises**: computer-misuse law turns on access being unauthorised, so the policy is where you say that the described testing, on the listed assets, is permitted. Second, it **promises non-pursuit**: you will not bring civil action or refer a good-faith in-scope researcher for prosecution. Third, it **commits support**: if a third party takes action anyway, you will state publicly that the activity was authorised. The limits matter as much as the promise. You can only authorise access to systems you control — not your cloud provider's infrastructure, not another customer's data, not anything a prosecutor decides independently. It is conditioned on good faith: stop at proof, take the minimum evidence, do not degrade the service, do not demand payment. And discretionary wording — "we may choose not to pursue" — is worse than silence, because a researcher reads the clause before touching anything and treats hedging as a threat.

go deeper

for a junior

Know that the clause is a written promise not to pursue legal action against good-faith researchers, and that it lives in the policy rather than in the security contact file.

for a middle

Explain the mechanism: computer-misuse law turns on access being unauthorised, so the clause supplies the authorisation. Be able to list what it cannot cover, especially third-party systems and other customers' data.

for a senior

Show judgment about drafting: define good faith as concrete instructions, add an explicit stop-and-report path for accidental scope breaches, and be able to explain why hedged wording drives researchers to publish instead.

for a principal

Own the argument with legal counsel. The instinct to reserve every right produces a clause that increases exposure, and you should be able to frame that trade in terms of which outcome the business prefers: a private report or a public talk.

## Why the clause exists at all Computer-misuse statutes across most jurisdictions criminalise access that is **unauthorised**. Nothing about probing a login form is inherently illegal; what makes it a crime is the absence of permission. That is a legal fact with a very practical consequence: the person best placed to remove the criminality of good-faith security research on your product is *you*, in writing, in advance. A vulnerability disclosure policy without a safe-harbour section is asking strangers to commit a crime on your behalf and hope you are in a good mood afterwards. This is why the clause is the section experienced researchers read first. Everything else in the policy — the contact address, the scope list, the response commitments — is operational. The safe-harbour clause is the part that determines whether they touch the system at all. ## The three components **1. Authorisation.** State plainly that the activities described are authorised access to the named assets for the purposes of security research. This is the load-bearing sentence. Be specific about technique as well as target: automated scanning at what rate, whether account creation is permitted, whether testing the mobile client counts. **2. Non-pursuit.** A commitment that you will not initiate civil action and will not refer the researcher to law enforcement for activity that stayed within the policy. Say it without conditions you cannot articulate. **3. Support against third parties.** The strongest clauses add: if someone else brings an action arising from research that followed this policy, we will make it known that the activity was authorised. You cannot promise the outcome, but you can promise to show up. ## What safe harbour cannot cover This is where candidates over-claim, and it is the part interviewers probe. - **Other people's systems.** You may authorise access to what you control. If your product runs on rented infrastructure, that provider's own terms still apply to the researcher, and you cannot waive them. Name that boundary explicitly and tell researchers to report suspected provider issues to you rather than probe upstream. - **Other people's data.** Your other customers did not sign your policy. Authorising a researcher to read a real tenant's records is not yours to give, which is why scope and safe harbour must be written together. - **Criminal prosecution as such.** A prosecutor is not a party to your policy. Your non-referral and your public statement of authorisation are strong practical protection; they are not immunity, and a candidate who claims they are has misunderstood the mechanism. - **Bad faith.** Extortion, exfiltrating data beyond what proves the bug, deliberately degrading availability, selling the finding, or continuing after being asked to stop all fall outside. Say so, in those terms, so the boundary is visible rather than improvised later. ## Good-faith conditions worth stating Good policies convert "good faith" from a vibe into instructions: stop at the first proof; take the minimum evidence needed to demonstrate impact; do not access, modify or delete data belonging to others; do not run load or denial-of-service tests; no social engineering of staff, customers or suppliers; no physical intrusion; report promptly and keep the details confidential while a fix is prepared. Each of those has been a real dispute somewhere, and each is cheap to pre-agree. Also write down what happens when a researcher **accidentally** steps out of scope, because they will. The right commitment is: if you realise you have gone beyond the policy, stop, tell us immediately, and we will treat the good-faith attempt as covered. Without that sentence the rational move for a researcher who has just tripped over live data is to say nothing — which leaves you with an unreported exposure and no idea it happened. ## Failure modes to recognise - **Discretionary language.** "We may, at our sole discretion, decline to pursue legal action" is a lawyer keeping options open and a researcher reading a threat. It converts your policy into a reason to disclose publicly instead. - **A gag as a precondition.** Requiring a signed NDA or a permanent promise of silence before you will accept a report is coercive; researchers refuse, and the finding goes public with the refusal attached to it. - **Safe harbour buried on page four.** If it is not adjacent to scope and easy to find, it is not doing its job. - **A clause with no scope.** Authorisation without a defined asset list is either meaningless or far broader than you intended. The short version to carry into an interview: safe harbour is authorisation plus a promise, bounded by what you actually own, conditioned on behaviour you have described in advance. Get the boundaries wrong in either direction and the clause either fails to protect the researcher or promises something that was never yours to promise.

  • What behaviour should the policy require of a researcher for safe harbour to hold?
    Stop at the first proof; take the minimum evidence that demonstrates impact; do not access, alter or retain other people's data; no load or denial-of-service testing, social engineering or physical intrusion; report promptly and keep details confidential while a fix is prepared. Spelling these out turns good faith from an argument after the fact into an agreement before it.
  • Why is a discretionary safe harbour worse than none at all?
    Because researchers read the clause before they touch anything. "We may decline to pursue action" tells them the decision is yours to make after they are already exposed, so the low-risk path becomes publishing without contacting you. Silence at least leaves ambiguity; hedged wording is an explicit reservation of the right to sue.
  • Can your safe harbour cover a researcher who probes the cloud provider hosting your product?
    No. You can only authorise access to systems you control, and your provider's terms bind the researcher independently of your policy. Draw the boundary explicitly, list the provider-owned surfaces as out of scope, and ask researchers to report suspected upstream issues to you so you can escalate through your own relationship.

saying these in an interview costs you the question

  • Claims safe harbour makes the research legal in every respect
  • Promises immunity from criminal prosecution
  • Requires an NDA before accepting a report
  • Extends the promise to a cloud provider's infrastructure
  • Treats safe harbour as boilerplate nobody reads
  • Leaves good faith undefined and argues about it afterwards

context

open as a page

What is an RFC 9116 security.txt file, and where must it be served?

level: juniorimportance: should knowfreq 52%

basics

~20 s

security.txt is a plain-text file, standardised by RFC 9116, that tells a researcher how to report a vulnerability to you. Serve it over HTTPS at /.well-known/security.txt with at least one Contact URI and an Expires date.

open as a page

Your VDP covers a multi-tenant B2B analytics product: how do you scope tenant-isolation testing?

level: seniorimportance: should knowfreq 41%

basics

~10 s

Authorise isolation testing only between tenants the researcher controls: let them self-register a second trial account and probe across their own two. Real customer data stays out of scope, with an explicit stop-and-report rule.

open as a page

Leadership wants a paid bug bounty before you have a VDP or a PSIRT — what do you advise?

level: principalimportance: nice to knowfreq 34%

basics

~10 s

Publish and staff a vulnerability disclosure policy first. A bounty multiplies inbound reports without creating anyone to triage or fix them; the binding constraint is response and remediation capacity, not researcher supply.

open as a page