Status DataClose notification

Vulnerability Disclosure Program

HackenProof's vulnerability disclosure platform gives your organization a clear channel for receiving, triaging, and resolving security reports from the outside world with built-in protection against spam and AI-generated noise.
Safe Harbor IncludedSpam & AI Noise FilteringISO 29147 & 30111 Aligned24/7 Report Validation

What Is a Vulnerability Disclosure Program?

A Vulnerability Disclosure Program (VDP) is a public, structured way for researchers, users, and partners to report security issues without fear of legal consequences. It works through three layers: the platform, the reporting program, and the policy that defines scope, safe harbor, and report handling.
01

The platform that hosts everything

Hosts the program, submissions, and workflow.
02

The program researchers submit to

The public channel researchers submit reports to.
03

The policy that governs it

Defines scope, safe harbor, and report handling.

HackenProof's VDP in Numbers

9+Years of Experience
85,000+Validated Vulnerability Reports
2-HourFirst validation SLA
24/7Validation coverage
ISO29147 & 30111 aligned

Why Run a VDP?

A VDP gives outside researchers a legitimate, no-friction way to tell you about a security issue before it becomes a bigger problem. Here's what that gets you.

Create a safe harbor

Without a clear reporting channel, most researchers won't bother telling you about a flaw — or worse, they'll disclose it publicly. A VDP gives them a legitimate, low-friction way to reach you first.
Secure reporting channel
Safe Reporting ChannelGood-Faith ProtectionPrivate DisclosureDirect Researcher Contact

Build security trust

A public VDP is visible proof that your organization takes security seriously — to customers, partners, and auditors alike.
Public security commitment
Public Security CommitmentCustomer ConfidencePartner AssuranceAuditor Visibility

Meet compliance expectations

Regulations like GDPR and HIPAA increasingly expect a vulnerability reporting mechanism to be in place.
Compliance checklist
GDPR AlignmentHIPAA ExpectationsDocumented ProcessReporting Mechanism

Catch issues early

Reports come in before problems escalate, giving your team time to fix things before they're exploited or disclosed elsewhere.
Early vulnerability detection
Early DetectionFaster TriageLower Exploit RiskPrevent Public Disclosure

Vulnerability Disclosure Program vs. Bug Bounty

A VDP is, in practice, a bug bounty without the payments, which means the machinery around payment disappears too.
Vulnerability Disclosure ProgramBug Bounty Program
RewardNone (discretionary)Paid, based on severity
Reward rangeNot requiredDefined upfront
Researcher KYCOptionalRequired
Triage & validationIncludedIncluded
Spam & AI-noise filteringIncludedIncluded
Fix verification (retest)IncludedIncluded

How Does VDP Work?

From the moment a researcher submits a report to the moment it's fixed, here's how a report moves through your VDP.

Receive

A researcher finds an issue and submits a report through your live VDP.
1

Validate & Triage

Your team or HackenProof's reviews the report and confirms whether it's a real, actionable issue.
2

Communication

We stay in the loop with the researcher if more detail is needed.
3

Remediate

Once you fix the issue, we can verify the fix. We can also provide reporting and trend data so you can track how your program is performing over time.
4

A VDP Isn't Just Good Practice — Increasingly, It's the Law

Running a bug bounty is rarely a legal requirement. Having a way to receive and act on vulnerability reports increasingly is.
European Union

EU — now mandatory under new law.

The NIS2 Directive and the Cyber Resilience Act (CRA) make coordinated vulnerability disclosure a legal obligation for a broad range of companies operating in or selling to the EU. GDPR adds the expectation that organizations handling personal data can receive and respond to security issues.
United States

US — mandatory for federal agencies, expected everywhere else.

CISA Binding Operational Directive 20-01 requires every federal civilian agency to publish a VDP and sets the market standard enterprises are now measured against. NIST frameworks build the same intake-and-response process into their core guidance.
International standards

International standards.

ISO/IEC 29147 (vulnerability disclosure) and ISO/IEC 30111 (vulnerability handling) define how a VDP should receive, process, and resolve reports — the blueprint regulators point to.
EU certification

EU certification.

ENISA builds coordinated disclosure into EU cybersecurity certification schemes (EUCC), with a European vulnerability database now taking shape.
US healthcare

US healthcare (HIPAA).

HIPAA doesn't name a VDP directly, but its Security Rule requires a process to identify and remediate vulnerabilities — a VDP is a practical way to support that obligation.
A documented VDP is one of the most straightforward ways to satisfy several of these frameworks at once.
Not legal advice — confirm applicability with your compliance team.

Vulnerability Disclosure Policy

Every HackenProof VDP runs on a clear policy (rules) that sets expectations for both sides:
Scope

Scope

Which assets are covered
Safe harbor

Safe harbor

A commitment not to pursue legal action against good-faith researchers who follow the rules
No guaranteed reward

No guaranteed reward

Recognition-based by default; any reward is fully discretionary, with no set range
Optional KYC

Optional KYC

Researcher verification is available if you want it, but not required
Report SLA

Report SLA

Response commitments on how quickly reports get acknowledged and triaged

What Types of VDP Do We Offer?

Choose how your VDP reaches researchers — hosted on our platform today, or embedded directly on your own site soon.
A VDP program page hosted on the HackenProof platform

Hosted on the HackenProof Platform

Your VDP lives on HackenProof, with a branded program page and direct researcher submission — no setup required on your end.
  • Hosted on HackenProof
  • Branded program page
  • Direct researcher submissions
  • No setup required
COMING SOON
A VDP widget embedded on your own website

Embeddable Widget (iFrame)

Embed a VDP widget directly on your own website. Reports are submitted via API, with no researcher login required — every submission comes to your HackenProof account.
  • Embedded on your website
  • Reports submitted via API
  • No researcher login required
  • Reports sent to your HackenProof account
FAQ

Have questions?!
We've got you!

Didn't find the answer? 👇🏻

Let’s Secure Your Product Together

Please fill in the form below or mail us at [email protected]
Full name *
Work email address *
Company name *
Company website *
Your contact info *
Telegram
Signal
WhatsApp
WeChat
Your primary goal *
arrow down
Run a Bug BountyConduct a Crowdsourced AuditImprove security score and reputationBuild a strategic partnershipGet a professional triage service for the reports
How did you hear about us?
arrow down
Search engineSocial mediaReferral or word of mouthEvent or conferenceBlog or articleOther
Tell us more about your request
I have read the Privacy Notice and agree to the Terms and Conditions
Subscribe to HackenProof Blog