RootBounty follows coordinated vulnerability disclosure: details are made public only once the affected organisation has had a fair chance to fix the issue.
What is public
- Hacktivity shows, for public programs, that a report exists, who submitted it (unless the researcher's profile is private), its severity and its status — submitted, triaged, accepted or closed.
- Report titles stay private until the company discloses a closed report; the full report only when both parties agree.
Timelines
- The company acknowledges the report within the first-response time its program publishes.
- Valid reports are triaged and fixed within a reasonable time for their severity.
- Once a report is closed the company may publish its title. Publishing the full report needs both the researcher and the company to agree; either can propose it, decline it or withdraw it later. Attachments and internal notes are never published. RootBounty mediates disagreements.
Safe harbor
Research carried out in good faith, within a program's scope and guidelines, is authorised by that program. Companies commit not to pursue legal action against it and to support researchers if a third party does.