Tools DNS Security TXT, Five Years On Five years after we proposed publishing your security contact in DNS, the standard has one canonical home, a required freshness field, an Internet-Draft, and 181 domains found in the wild.
Tools disclose.io/platforms: a community-maintained list of every bug bounty and VDP platform we know about A single, canonical, community-maintained list of every bug bounty and vulnerability disclosure platform we know about — global, regional, and vertical-specific. Vendor-agnostic by design.
Tools The disclose.io Maturity Model: a six-level ladder for vulnerability disclosure programs The disclose.io Maturity Model is a six-level ladder — from 'no contact' to 'full safe harbor with CVD' — that underpins every entry in the new directory. Here's how it works, and who it's for.
Tools Introducing lookup.disclose.io: One Tool to Find All Security Contacts (Now in Beta) Announcing lookup.disclose.io beta: universal security contact lookup for any digital asset. Find bug bounty programs, security.txt, and VDP contacts instantly.
Research A brief history of vulnerability disclosure and bug bounty Explore the evolution of vulnerability disclosure from the early days of full disclosure debates through the emergence of bug bounty programs. A comprehensive three-part series by Dennis Fisher covering the history that shaped modern security research.
Community VIDEO: An intro to disclose.io and hacker safety Watch this introductory video explaining what disclose.io does, why hacker safety matters, and how organizations can implement vulnerability disclosure programs that protect both researchers and their systems.
Tools dnssecuritytxt DNS-based discovery of security.txt files using the _securitytxt TXT record. Learn how dnssecuritytxt enables organizations to publish vulnerability disclosure contact information through DNS, complementing the traditional .well-known/security.txt approach.