Business services • Responsible disclosure • Technical triage

Managed VDP and triage

A professional channel for receiving and managing security reports.

We help organizations launch, receive, validate and manage vulnerability reports submitted by security researchers through a clear and structured process.

Policy and scope Report intake Validation and severity Follow-up
The service

What a VDP is

A Vulnerability Disclosure Program or VDP provides an authorized channel through which security researchers can responsibly report vulnerabilities. It defines which systems may be tested, what activity is permitted and how a report should be submitted.

A well-defined process helps reports reach the right team, prevents fragmented communication and allows the organization to respond consistently to people who disclose a potential security issue.

The problem we solve

Why use specialist support to manage a VDP

Receiving a report is only the beginning: it must then be understood, reproduced, prioritized and coordinated.

Reports may contain incomplete information, duplicates, false positives or impacts that are difficult to assess. Technical triage quickly separates valid findings from submissions that do not represent a real risk and passes only the relevant information to the internal team.

It also supports professional communication with the researcher, prevents conflicting messages and maintains follow-up until the report can be closed under the organization's defined process.

What we do

The three parts of the service

The service can support both organizations launching their first VDP and those already receiving reports.

VDP setup

We help define the scope, participation rules, contact channel, disclosure policy and security.txt file.

Report intake and triage

We review incoming reports, verify that they are in scope, reproduce the findings and assess their impact and severity.

Communication and follow-up

We support communication between the researcher and the organization, pass information to the responsible team and provide the agreed follow-up through closure.

Flexible scope

What the service can include

The proposal is configured around report volume, the existing process and the level of support required.

Creation or review of the VDP policy and participation rules.
Scope and exclusion definition to prevent ambiguity.
security.txt configuration and public contact channel setup.
Report intake, validation and classification for incoming submissions.
Researcher communication and escalation to the responsible team.
Follow-up, retesting and periodic reporting where included in the contracted service.
First-hand experience

We apply the same principles internally

SixHack Academy operates a public vulnerability disclosure program with a security policy, security.txt file and Hall of Fame recognizing valid reports.

Different concepts

VDP versus bug bounty

A VDP creates a channel and process for responsible vulnerability reporting. It does not necessarily involve monetary rewards. A bug bounty program typically adds payments for valid findings and more active researcher participation.

SixHack Academy's service focuses on process setup, report intake and technical triage. Specific terms, response times and any recognition policy are agreed with each organization.

FAQ

Frequently asked questions

What is the difference between a VDP and a bug bounty?
A VDP establishes a channel and process for responsible vulnerability reporting. A bug bounty usually adds monetary rewards and more active researcher participation. A VDP does not necessarily involve rewards.
Can you create a VDP from scratch?
Yes. We can help define the scope, rules, contact channel, disclosure policy and security.txt file before report management begins.
What happens when a vulnerability report is received?
We review its scope, reproducibility and impact. It is then classified, the relevant information is passed to the responsible team and the agreed communication with the researcher is managed.
Does the service include retesting?
Follow-up and retesting can be included in the contracted service to verify remediation and support the technical closure of the report.

Do you receive security reports and need help managing them?

We can help define the process, validate findings and maintain clear technical communication with researchers.