disclose.io · A living index · 2026-07-25

The State of Vulnerability Disclosure

A snapshot of 27,584 organisations indexed by directory.disclose.io, mapped against the disclose.io maturity model. Each dot below is one organisation. Click for details; filter to find specific programs.

183
Level 5 · Full + CVD
731
Level 4 · Full Safe Harbor
1,597
Level 3 · Partial
24,600
Level 2 · Basic VDP
473
Level 1 · Contact only
New The safe-harbor scoreboard for the world's biggest companies Explore the Top 100
L5

Full Safe Harbor + CVD

183 orgs · 0.7%
L4

Full Safe Harbor

731 orgs · 2.7%
L3

Partial Safe Harbor

1,597 orgs · 5.8%
L2

Basic VDP

24,600 orgs · 89.2%
L1

Contact Only

473 orgs · 1.7%

Each dot is one organisation. Hover for name & score; click for full criteria, contacts, and links. Sized by tier — narrower upper tiers reflect rarity, not screen real estate.

See it in action

From blank page to defensible policy in under a minute

policymaker.disclose.io walks any org through four short steps — name & contact → CVD timeline → policy URL → download. The output is legally-reviewed boilerplate you can hand to counsel and ship.

It's free, open-source, available in 12 languages, and fully customizable. The hard work — drafting safe-harbor language that holds up, mapping CVD timelines, the security.txt format — is already done.

No narration. Real interactions. ~36 seconds.
Where to next

Three roles in this ecosystem

Wherever you sit, the disclose.io stack has a place for you.

The cost of getting it wrong

Threats against researchers

An archive of legal threats made against security researchers engaged in good-faith vulnerability disclosure, plus open submissions still under research. Source: disclose/research-threats.

91 confirmed
20 pending under research
Spanning 2000–2026
Confirmed (91) Pending research (20) Hover for details · click to jump to the entry
20002002200420062008201020122014201620182020202220242026 2000-08-17 · Motion Picture Association of America (MPAA) & DVD Copy Control Association (DVD CCA) · 2600: The Hacker Quarterly2001-07-16 · Adobe Systems Incorporated · Dmitry Sklyarov & ElcomSoft2001-04-23 · Secure Digital Music Initiative (SDMI), Recording Industry Association of America (RIAA) and Verance Corporation · Ed Felten2002-07-30 · Hewlett-Packard Development Company, L.P. (HP) · SNOsoft2002-03-18 · Harris County District Court · Stefan Puffer2003-09-30 · Blackboard Transaction System · Billy Hoffman and Virgil Griffith2003-08-18 · Tornado Development, Inc. · Bret McDanel2003-02-05 · Epic Games · Luigi Auriemma / PivX Solutions2005-07-29 · Cisco Systems, Inc. · Mike Lynn / ISS2005-03-25 · Sybase, Inc. · Next-Generation Security Software2006-12-07 · Oracle Corporation · Argeniss2006-09-02 · SimpleBlog · Vipsta & MurderSkillz2006-04-28 · University of Southern California · Eric McCarty2007-12-06 · Autonomy Corp., PLC · Secunia2007-07-29 · U.S. Customs · Halvar Flake2007-04-17 · BeThere (Be Un limited) · Sid Karunaratne2007-02-27 · HID Global · Chris Paget/IOActive2008-10-24 · Google · Charlie Miller2008-09-12 · Carleton University · Mansour Moufid2008-08-13 · Sequoia Voting Systems · Ed Felten2008-08-09 · Massachusetts Bay Transit Authority · Zach Anderson, RJ Ryan and Alessandro Chiesa2008-08-01 · Apple · Charles Edge / 318 Inc.2008-07-09 · NXP (formerly Philips Semiconductors) · Radboud University Nijmegen2008-07-02 · Apple · Unamed 'Apple Insiders'2009-07-18 · RSA · Scott Jarkoff2009-07-17 · Comerica Bank · Lance James2009-06-30 · ATM Vendors (unnamed, presumed Triton) · Barnaby Jack / Juniper Networks2009-06-06 · Orange.fr · HackersBlog2010-08-23 · n/a · Hari Prasad, Netindia2010-08-22 · Indian Police (Mumbai) · Hari Prasad2010-07-26 · Financial Industry Client (unspecified) · Varun Uppal and Gyan Chawdhary2010-07-15 · Taiwanese / Chinese agencies (unnamed) · Wayne Huang, Armorize CTO2010-07-15 · Taiwanese Government · Wayne Huang, Armorize Technologies Inc.2010-06-29 · ATM Vendors (unnamed) · Raoul Chiesa2011-11-22 · Carrier IQ · Trevor Eckhart2011-10-13 · First State Superannuation · Patrick Webster2011-08-16 · (none) · Riley Hassel / Shane Macaulay2011-08-01 · Trans Link Systems · Brenno de Winter2011-05-18 · Siemens / Department of Homeland Security (DHS) · Dillon Beresford / NSS Labs2011-04-27 · Magix AG · Acidgen2011-03-21 · German telecommunications firm (unspecified) · Thomas Roth2012-10-25 · (unknown international utility) · Ralph Langner2012-10-19 · Hewlett-Packard · Kurt Grutzmacher2012-10-10 · (none) · Pirate Bay founders Peter Sunde and Fredrik Neij2012-07-29 · (unknown) · Sergey Gordeychik / Denis Baranov, Positive Technologies2012-05-28 · E-Soft (UK) · Eric Romang2012-01-31 · Smart Grid Meter Vendor (unnamed) · Don Weber / InGuardians2012-01-31 · Smart Grid/Meter Vendor (unspecified) · Don Weber / InGuardians2013-12-16 · ZippyYum · Daniel Wood2013-11-10 · Christchurch Public Transport Card (ECan) · William "AmmonRa" Turner2013-07-26 · Volkswagen · Flavio Garcia, University of Birmingham2013-07-09 · VideoLAN Organization · Secunia2013-06-13 · Zamfoo · Patrick2013-04-30 · Wowza Media Systems · Michal J.2013-04-05 · Keeper · Fox IT2013-01-20 · Dawson College / Skytech · Ahmed Al-Khabaz2014-07-09 · FireEye · Jean-Marie Bourbon2014-01-15 · Covered California · Kristian Erik Hermansen and Matt Ploessel2014-01-08 · Public Transport Victoria · Joshua Rogers2015-12-23 · Infoba · Henrik Høyer2015-10-06 · Unspecified · Gianni Gnesa2015-09-25 · Good Technology · Max Moser, Tobias Ospelt, David Gullasch (modzero)2015-08-13 · FireEye · Felix Wilhelm, ERNW2015-07-13 · Impero Software · slipstream (@TheWack0lian2015-07-07 · Magic Software Argentina · Joaquín Sorianello2015-05-04 · CyberLock · Mike Davis / IOActive2015-03-26 · Blue Coat · Raphael Rigo2016-12-07 · PwC · ESNC GmbH2016-11-17 · Chase Bank · Chad Scira2016-06-18 · Nerium International · Steven Jensen2017-12-20 · Keeper · Dan Goodin2017-08-03 · MIT @MIT · Bill Demirkapi @D4stiny2019-11-05 · Boeing @Boeing · Chris Kubecka2019-07-17 · Budapesti Közlekedési Központ (BKK) · Unknown 18 Year Old2020-09-10 · Giggle · Digital Interuption2020-03-06 · Talkspace @Talkspace · John J Hacking2020-01-30 · Iowa Supreme Court, Dallas County Sheriff Department · Coalfire Red Teamers Arrested at work2021-10-21 · Apple, @apple · Denis Tokarev, @illusionofchaos2021-10-15 · The State of Missouri · St. Louis Post-Dispatch2021-08-04 · CDU (German political party) · CERT, Politics, hacktivism, back-tracking2021-07-13 · Apple, @apple · Corellium, @corellium,2021-04-29 · what3words, @What3Words · Aaron Toponce2021-03-25 · Apperta Foundation Supported by NHS England, NHS Digital · Rob Dyke2021-03-02 · Xerox · Raphaël Rigo / Airbus Security LabPending #35 · Quebec QR Code containing JWT of patient medical records legal issuePending #25 · Ian Linkletter & Proctorio Pending #23 · FireEye & RazorEQXPending #12 · Remove VLC from the repo2022-02-12 · Cole County Prosecuting Attorney @ The State of Missouri · Josh Renaud - View StatementPending #44 · Cloudflare threatened Tavis OrmandyPending #43 · Possible addition: Facial recognition technology is being used for multiple purposes from law enforcement. Lawsuit (India)Pending #42 · HUGE Litigation - Proctorio lawsuit - Many partiesPending #41 · Alberto Daniel Hill longstanding issue with local law enforcement.Pending #39 · VW Fired Senior Employee After They Raised Cyber Security Concerns2023-12-27 · NEWAG · Serwis Pojazdów Szynowych (SPS), Dragon Sector2023-07-23 · Ford @ford, Rapid7 @rapid7 · Ben Sadeghipour2023-07-16 · Arm Ltd · Maria Markstedter "Azeria"2023-04-12 · FreeHour · Giorgio Grigolo, Michael Debono, Luke Bjorn Scerri and Luke CollinsPending #52 · Boston Charlie Card - DEFCON 2023Pending #48 · 2017 Unnamed BAC Company2024-07-29 · [City of Columbus, Ohio]() · Connor Goodwolf2024-01-18 · Modern Solution GmbH & Co. KG · Unnamed security researcherPending #58 · Connor Goodwolf vs Franklin County CityPending #56 · Iota threatened researcherPending #63 · Bobdahacker Blog - Restaurant Brands International (RBI) / Burger King / Cyble DMCA TakedownPending #62 · Belgium is unsafe for CVDPending #61 · McNally vs Proven LocksPending #59 · Julien | MrTuxracer vs SynackPending #66 · David Maynor/Johnny Cache vs ApplePending #65 · Survey re: Threats - FYI / NewsPending #64 · Jon Gaines Fired After Reporting 50 CVEs for LPR Surveillance
Year Entity Researcher(s) Topic
2024 [City of Columbus, Ohio]() Connor Goodwolf City gets hacked and sues researcher for investigating the Dark Web data.
2024 Modern Solution GmbH & Co. KG Unnamed security researcher Researcher reports vulnerability, vendor denies it, researcher ends up being sentenced by a court.
2023 NEWAG Serwis Pojazdów Szynowych (SPS), Dragon Sector Security researchers find disturbing DRM on trains, get sued.
2023 Ford @ford, Rapid7 @rapid7 Ben Sadeghipour Rapid7 asks NahamSec to take down a video about Ford.
2023 Arm Ltd Maria Markstedter "Azeria" Arm submits abuse report to researcher's domains about IP.
2023 FreeHour Giorgio Grigolo, Michael Debono, Luke Bjorn Scerri and Luke Collins Students arrested, stripped naked, violated by Police.
2022 Cole County Prosecuting Attorney @ The State of Missouri Josh Renaud - View Statement Prosecutor Drops Charges After Four "Anxious" Months
2021 Apple, @apple Denis Tokarev, @illusionofchaos DMCA Takedowns of Mirror
2021 The State of Missouri St. Louis Post-Dispatch State law vs. Good-faith research, alleged hacktivism.
2021 CDU (German political party) CERT, Politics, hacktivism, back-tracking Lilith Wittmann
2021 Apple, @apple Corellium, @corellium, Relentless dissmissed copyright infringement lawsuits of good faith research platform
2021 what3words, @What3Words Aaron Toponce "Proprietary" Worldlists
2021 Apperta Foundation Supported by NHS England, NHS Digital Rob Dyke Sensitive Public Info
2021 Xerox Raphaël Rigo / Airbus Security Lab Attacking Xerox Multi Function Printers
2020 Giggle Digital Interuption Giggle App
2020 Talkspace @Talkspace John J Hacking Talkspace
2020 Iowa Supreme Court, Dallas County Sheriff Department Coalfire Red Teamers Arrested at work Red team falsely arrested.
2019 Boeing @Boeing Chris Kubecka Companies without disclosure policies
2019 Budapesti Közlekedési Központ (BKK) Unknown 18 Year Old Transit System Security
2017 Keeper Dan Goodin Keeper sues reporter over vulnerability story
2017 MIT @MIT Bill Demirkapi @D4stiny Web Site Security
2016 PwC ESNC GmbH PwC ACE Software
2016 Chase Bank Chad Scira Web Site Security
2016 Nerium International Steven Jensen Vulnerability in customer portal
2015 Infoba Henrik Høyer Vulnerability in Infoba solutions
2015 Unspecified Gianni Gnesa Surveillance camera vulnerabilities
2015 Good Technology Max Moser, Tobias Ospelt, David Gullasch (modzero) XSS in Good for Enterprise administration console
2015 FireEye Felix Wilhelm, ERNW Finding/reporting vulnerabilities in FireEye products
2015 Impero Software slipstream (@TheWack0lian Disclosing vulnerabilities in their product
2015 Magic Software Argentina Joaquín Sorianello Vulnerabilities in MSA Vot.ar Electronic Voting System
2015 CyberLock Mike Davis / IOActive Vulnerabilities in a product
2015 Blue Coat Raphael Rigo Security assessment information on Blue Coat ProxySG technology
2014 FireEye Jean-Marie Bourbon Security flaws in FireEye's Malware Analysis System
2014 Covered California Kristian Erik Hermansen and Matt Ploessel Security flaws in Covered California website
2014 Public Transport Victoria Joshua Rogers Security flaws in PTV website
2013 ZippyYum Daniel Wood Insecure Data Storage in iOS Subway ordering app
2013 Christchurch Public Transport Card (ECan) William "AmmonRa" Turner Insecure Public Transport Card System
2013 Volkswagen Flavio Garcia, University of Birmingham Security flaws in Volkswagen cars
2013 VideoLAN Organization Secunia Security flaws in VLC Media Player
2013 Zamfoo Patrick Security flaws in Zamfoo's products
2013 Wowza Media Systems Michal J. Vulnerabilities in the media server's authentication
2013 Keeper Fox IT Security vendor threatens legal action against research group
2013 Dawson College / Skytech Ahmed Al-Khabaz Security flaws in Skytech's Omnivox portals, used by schools
2012 (unknown international utility) Ralph Langner Nuclear power plant vulnerabilities (SCADA)
2012 Hewlett-Packard Kurt Grutzmacher Huawei / H3C router vulnerabilities
2012 (none) Pirate Bay founders Peter Sunde and Fredrik Neij Talk titled "Data is Political"
2012 (unknown) Sergey Gordeychik / Denis Baranov, Positive Technologies SCADA vulnerabilities including Siemens
2012 E-Soft (UK) Eric Romang Video of Metasploit Digital Music Pad SEH overflow exploitation module
2012 Smart Grid Meter Vendor (unnamed) Don Weber / InGuardians Smart Grid Vulnerabilities
2012 Smart Grid/Meter Vendor (unspecified) Don Weber / InGuardians Smart Grid Meter Security Assessment Tool Release
2011 Carrier IQ Trevor Eckhart Carrier IQ software logs excessive information
2011 First State Superannuation Patrick Webster Direct Object Reference vulnerability in FSS website
2011 (none) Riley Hassel / Shane Macaulay Google Android Vulnerabilities
2011 Trans Link Systems Brenno de Winter OV Transit Payment System Vulnerabilities
2011 Siemens / Department of Homeland Security (DHS) Dillon Beresford / NSS Labs SCADA vulnerabilities
2011 Magix AG Acidgen Buffer overflow in Music Maker 16 software (version 16.0.2.4)
2011 German telecommunications firm (unspecified) Thomas Roth Amazon EC2-based password cracking software
2010 n/a Hari Prasad, Netindia Voting Machine vulnerability research
2010 Indian Police (Mumbai) Hari Prasad Vulnerabilities in Electronics Corporation of India (ECIL) Electronic Voting Machines
2010 Financial Industry Client (unspecified) Varun Uppal and Gyan Chawdhary High-Speed Trading System Hacks
2010 Taiwanese / Chinese agencies (unnamed) Wayne Huang, Armorize CTO Analysis of China's government-backed hacking initiatives
2010 Taiwanese Government Wayne Huang, Armorize Technologies Inc. The Chinese Cyber Army: An Archaeological Study from 2001 to 2010
2010 ATM Vendors (unnamed) Raoul Chiesa ATM Vulnerabilities
2009 RSA Scott Jarkoff Navy Federal Credit Union Web Site Flaws
2009 Comerica Bank Lance James XSS / Phishing vulnerabilities on Comerica site
2009 ATM Vendors (unnamed, presumed Triton) Barnaby Jack / Juniper Networks ATM Vulnerabilities
2009 Orange.fr HackersBlog Multiple Vulnerabilities [1] [2]
2008 Google Charlie Miller Vulns in T-Mobile Google Phone
2008 Carleton University Mansour Moufid Used keylogger to expose student information
2008 Sequoia Voting Systems Ed Felten Voting Machine Audit
2008 Massachusetts Bay Transit Authority Zach Anderson, RJ Ryan and Alessandro Chiesa Electronic Fare Payment (Charlie Card/Charlie Ticket)
2008 Apple Charles Edge / 318 Inc. FileVault encryption system weaknesses
2008 NXP (formerly Philips Semiconductors) Radboud University Nijmegen Mifare Classic Card Chip Security
2008 Apple Unamed 'Apple Insiders' Apple Security Response Team
2007 Autonomy Corp., PLC Secunia KeyView Vulnerability Research
2007 U.S. Customs Halvar Flake Security Training Material
2007 BeThere (Be Un limited) Sid Karunaratne Publishing ISP Router Backdoor Information
2007 HID Global Chris Paget/IOActive RFID Security Problems
2006 Oracle Corporation Argeniss Week of Oracle Bugs (WoOB)
2006 SimpleBlog Vipsta & MurderSkillz Reporting of an SQL injection to a vendor resulted in immediate, "legal threats."
2006 University of Southern California Eric McCarty Database programming error allows disclosure of student SSN and more
2005 Cisco Systems, Inc. Mike Lynn / ISS Cisco router vulnerabilities
2005 Sybase, Inc. Next-Generation Security Software Sybase Database vulnerabilities
2003 Blackboard Transaction System Billy Hoffman and Virgil Griffith Blackboard issued C&D to Interz0ne conference, filed complaint against students
2003 Tornado Development, Inc. Bret McDanel Secure Webmail Session Hijacking discovery
2003 Epic Games Luigi Auriemma / PivX Solutions Vulnerabilities in Unreal game engine
2002 Hewlett-Packard Development Company, L.P. (HP) SNOsoft Tru64 Unix OS vulnerability - DMCA based threat
2002 Harris County District Court Stefan Puffer Insecure wireless network discovery
2001 Adobe Systems Incorporated Dmitry Sklyarov & ElcomSoft Adobe eBook AEBPR Bypass
2001 Secure Digital Music Initiative (SDMI), Recording Industry Association of America (RIAA) and Verance Corporation Ed Felten Four Watermark Protection Schemes Bypass - DMCA based threat
2000 Motion Picture Association of America (MPAA) & DVD Copy Control Association (DVD CCA) 2600: The Hacker Quarterly DVD Encryption Breaking Software (DeCSS)

Pending — submitted, awaiting research

Open issues on the research-threats repo that are queued for confirmation and addition to the archive above.

#66 87d open · 2026-05-04
David Maynor/Johnny Cache vs Apple
research
#65 174d open · 2026-02-06
Survey re: Threats - FYI / News
research
#64 201d open · 2026-01-10
Jon Gaines Fired After Reporting 50 CVEs for LPR Surveillance
research
#63 285d open · 2025-10-17
Bobdahacker Blog - Restaurant Brands International (RBI) / Burger King / Cyble DMCA Takedown
research
#62 386d open · 2025-07-09
Belgium is unsafe for CVD
(no label)
#61 421d open · 2025-06-04
McNally vs Proven Locks
research
#59 462d open · 2025-04-24
Julien | MrTuxracer vs Synack
research
#58 699d open · 2024-08-30
Connor Goodwolf vs Franklin County City
research
#56 707d open · 2024-08-22
Iota threatened researcher
research
#52 1068d open · 2023-08-27
Boston Charlie Card - DEFCON 2023
(no label)
#48 1171d open · 2023-05-16
2017 Unnamed BAC Company
research
#44 1425d open · 2022-09-04
Cloudflare threatened Tavis Ormandy
research
#43 1604d open · 2022-03-09
Possible addition: Facial recognition technology is being used for multiple purposes from law enforcement. Lawsuit (India)
(no label)
#42 1607d open · 2022-03-06
HUGE Litigation - Proctorio lawsuit - Many parties
research
#41 1629d open · 2022-02-12
Alberto Daniel Hill longstanding issue with local law enforcement.
(no label)
#39 1647d open · 2022-01-25
VW Fired Senior Employee After They Raised Cyber Security Concerns
research
#35 1793d open · 2021-09-01
Quebec QR Code containing JWT of patient medical records legal issue
research
#25 1925d open · 2021-04-22
Ian Linkletter & Proctorio
(no label)
#23 1927d open · 2021-04-20
FireEye & RazorEQX
research
#12 1932d open · 2021-04-15
Remove VLC from the repo
(no label)
Open source · contributors and maintainers wanted

Saw a researcher get threatened? Help us document it.

Every entry keeps the ecosystem accountable, educates organizations and hackers alike, and gives policymakers something to point to. Three ways to help:

If you've been threatened

Security researchers don't have to face it alone.

The Security Research Legal Defense Fund is a 501(c)(3) nonprofit that funds legal representation for good-faith security researchers facing legal action — the same kind of threats archived above.

If you, or someone you know, is being threatened for good-faith research and vulnerability disclosure, the Defense Fund can help with legal counsel and emergency funding.

Where programs live

Bug bounty & VDP platforms

A community-curated index of crowdsourced security platforms — bug bounty, VDP, and triage services. Source: disclose/bug-bounty-platforms.

85 platforms
USA · 14
India · 5
Switzerland · 3
Australia · 3
United Arab Emirates · 3

Bug Hunt

Brazil
Programs
Private + Public
Leaderboard
Yes · view

BUGLOUD

United Arab Emirates
Programs
Private + Public

Butian

China
Programs
Private + Public
Leaderboard
Yes

Cyscope

Switzerland & Latam
Programs
Private + Public
Leaderboard
Yes
X / Twitter
@cy_scope

Gerobug

Indonesia
Programs
Self-hosted
Leaderboard
No

Hacckers

Israel
Programs
Private + Public

safehats

India
Programs
Private + Public
Leaderboard
Yes · view
Open source · contributors wanted

Run a platform, or know one we missed?

Platforms come and go fast. Help keep this list current — broken links, new launches, regional platforms we don't know about, anything.

The disclose.io stack

Tools that make this work in practice

A complete chain — from drafting a policy, to publishing it, to receiving reports safely, to coordinating disclosure.