Legal · Updated 28 September 2026

Disclosure policy

RootBounty follows coordinated vulnerability disclosure: details are made public only once the affected organisation has had a fair chance to fix the issue.

What is public

  • Hacktivity shows, for public programs, that a report exists, who submitted it (unless the researcher's profile is private), its severity and its status — submitted, triaged, accepted or closed.
  • Report titles stay private until the company discloses a closed report; the full report only when both parties agree.

Timelines

  1. The company acknowledges the report within the first-response time its program publishes.
  2. Valid reports are triaged and fixed within a reasonable time for their severity.
  3. Once a report is closed the company may publish its title. Publishing the full report needs both the researcher and the company to agree; either can propose it, decline it or withdraw it later. Attachments and internal notes are never published. RootBounty mediates disagreements.

Safe harbor

Research carried out in good faith, within a program's scope and guidelines, is authorised by that program. Companies commit not to pursue legal action against it and to support researchers if a third party does.