What is responsible disclosure?
Responsible disclosure, also called coordinated vulnerability disclosure, is a process for outside researchers to report security flaws privately so they can be fixed before becoming public. A vulnerability disclosure policy (VDP) states how to report and what to expect. A bug bounty adds payment for valid reports.
What the buyer is really asking
Can an outside researcher report a vulnerability to you, and will someone respond? Link to your security contact page or security.txt. A paid bug bounty is optional. A working inbox with a response commitment is not.
Other ways buyers ask it
Every one of these wants the same answer:
- “Do you have a responsible disclosure policy?”
- “Do you run a bug bounty program?”
- “How can security researchers report vulnerabilities to you?”
Evidence to have ready
- Your vulnerability disclosure page or security.txt file
- The bug bounty program page, if you run one
How Tyrvar answers this
Tyrvar treats every wording above as one question. You write the answer once, attach the evidence, and revisit it when your setup changes. Each buyer gets that approved answer no matter how their questionnaire words it. If you have not answered it yet, Tyrvar flags the question for you and does not make something up. Try it on your own questionnaire.