Skip to content
Vulnerability Disclosure Program

Turn every reported vulnerability into an opportunity to strengthen your security

A VDP is your official channel for anyone to report flaws to you in a safe, structured way. We manage it for you: you only receive what matters, already validated.

Why a VDP?

Every system has vulnerabilities, and sometimes it is someone on the outside, acting in good faith, who finds them. Imagine a researcher finds one in your systems and wants to let you know.

What happens then?

This is what usually happens without a VDP

How do they find you?

Without clear guidelines, tracking down your security team's contact details is not easy. The researcher wants to help, but has no idea where to start.

So they write wherever they can.

More often than not it lands in customer support or a generic inbox. From there, the message usually fails to reach the right people, or sits for weeks in an inbox. And email is not a safe channel for something as sensitive as a vulnerability either.

And if they get no reply…

Given enough time, they may decide to go public on their own, on social media or on their blog. That is what is known as full disclosure: the vulnerability becomes public before you have been able to fix it.

With a VDP, this story goes very differently

You give whoever wants to help you a single place, clear and secure, to report it. You get the warning in time, in an orderly way, and with the legal backing to handle it calmly.

Without a VDP the report scatters across several channels and one of them gets lost; with Secur0's VDP it comes in through a single place and arrives sorted by severity.

So, what is a VDP?

A Vulnerability Disclosure Program (VDP) is the formal process through which external researchers can report security flaws to you responsibly and without fear of legal retaliation.

It is a practice recommended by ENISA, CISA and NIST, among others, and increasingly a regulatory requirement.

Secur0 is a benchmark in vulnerability management and disclosure.

We do not just receive your reports: we handle them with the rigour of those who define the standard.

We are a CVE Numbering Authority (CNA) and we work in line with the ISO/IEC 29147 and 30111 standards, the ones that govern how vulnerabilities are received and handled worldwide.

INCIBE, Spain's National Cybersecurity Institute
CVE, Common Vulnerabilities and Exposures

This is how your VDP works, step by step

You publish your policy

We help you draft your disclosure policy and your security.txt file. Within minutes you have an official, visible channel where people can report to you.

You publish your policy

Researchers report through your channel

Any researcher who finds a flaw logs it in your program, with the rules and the legal framework clear from the very first moment.

Researchers report through your channel

We validate, triage and prioritise for you

We review every report, discard the noise and the duplicates, and validate what is real. Every valid vulnerability reaches you prioritised by severity.

We validate, triage and prioritise for you

You analyse and prove it

You follow everything from a single dashboard and generate evidence reports whenever you need them, for audits or for the board.

You analyse and prove it

Need a hand?

Tell us about your case and we'll help you.

Request a demo

Frequently asked questions

What is a VDP (Vulnerability Disclosure Program)?

A VDP is the official, structured channel through which external researchers can responsibly report the security flaws they find in your systems, without fear of legal retaliation. It sets clear rules (what can be tested, how to report and under what legal protection) and it is a practice recommended by ENISA, CISA and NIST.

How is a VDP different from a bug bounty?

The main difference is the reward: a VDP does not pay per vulnerability, it only manages and validates the report, whereas a bug bounty pays for every valid flaw according to its severity. A VDP is the first step towards receiving reports in an orderly way; a bug bounty adds a financial incentive to attract more and better researchers.

Is having a VDP mandatory?

Increasingly so. A VDP is already a requirement under regulations such as the CRA (Cyber Resilience Act) and it is part of the good practices demanded by frameworks like ISO/IEC 29147 and 30111. Even where it is not required by law, having one demonstrates security maturity to clients, auditors and regulators.

How long does it take to set up a VDP?

Very little. We help you draft your disclosure policy and your security.txt file, and within minutes you have an official, visible channel where researchers can start reporting.

Do I need a security team to run a VDP?

No. Secur0 runs the VDP end to end: we receive, filter, validate and prioritise the reports for you. Your team only gets the real vulnerabilities, already screened and ready to fix, without adding to their day-to-day workload.

What is a security.txt file?

It is a standard file published on your website (at /.well-known/security.txt) telling researchers how to report a vulnerability to you. It includes your security contact, your disclosure policy and its expiry date. It is the internationally recognised way of saying "this is where you can warn us".

How much does a VDP cost?

With a VDP you do not pay for each vulnerability found: the cost sits in managing and validating the reports, not in rewards. That makes it an affordable entry point for starting to receive security reports in an orderly way.

Get your VDP running without adding work to your team.

We run it end to end. You only get real vulnerabilities, prioritised and ready to fix.