VDP setup
We help define the scope, participation rules, contact channel, disclosure policy and security.txt file.
A professional channel for receiving and managing security reports.
We help organizations launch, receive, validate and manage vulnerability reports submitted by security researchers through a clear and structured process.
A Vulnerability Disclosure Program or VDP provides an authorized channel through which security researchers can responsibly report vulnerabilities. It defines which systems may be tested, what activity is permitted and how a report should be submitted.
A well-defined process helps reports reach the right team, prevents fragmented communication and allows the organization to respond consistently to people who disclose a potential security issue.
Receiving a report is only the beginning: it must then be understood, reproduced, prioritized and coordinated.
Reports may contain incomplete information, duplicates, false positives or impacts that are difficult to assess. Technical triage quickly separates valid findings from submissions that do not represent a real risk and passes only the relevant information to the internal team.
It also supports professional communication with the researcher, prevents conflicting messages and maintains follow-up until the report can be closed under the organization's defined process.
The service can support both organizations launching their first VDP and those already receiving reports.
We help define the scope, participation rules, contact channel, disclosure policy and security.txt file.
We review incoming reports, verify that they are in scope, reproduce the findings and assess their impact and severity.
We support communication between the researcher and the organization, pass information to the responsible team and provide the agreed follow-up through closure.
The proposal is configured around report volume, the existing process and the level of support required.
SixHack Academy operates a public vulnerability disclosure program with a security policy, security.txt file and Hall of Fame recognizing valid reports.
A VDP creates a channel and process for responsible vulnerability reporting. It does not necessarily involve monetary rewards. A bug bounty program typically adds payments for valid findings and more active researcher participation.
SixHack Academy's service focuses on process setup, report intake and technical triage. Specific terms, response times and any recognition policy are agreed with each organization.
We can help define the process, validate findings and maintain clear technical communication with researchers.