Program Active & Accepting Reports|Target: example.com & Subdomains
Example SecurityVulnerability Disclosure
Report Vulnerability
ISO 29147 & RFC 9116 Compliant Policy

Help Us Keep Our Products
& Subdomains Secure

We deeply value the security research community. If you have discovered a vulnerability across any of our web applications, APIs, or subdomains, please notify us under clear Safe Harbor protections.

Encrypted SubmissionsPGP Key ID: 0x49E82F10
First Response≤ 24 Hours
High Priority
LEGAL PROTECTIONS

Our Legal Safe Harbor Commitment

We will not pursue legal action against researchers who adhere to good-faith disclosure principles.

Good Faith Research

If you conduct security research in compliance with this policy, we consider your research authorized and will work with you to understand and resolve the issue promptly.

No Civil or Criminal Liability

We waive any potential Computer Fraud and Abuse Act (CFAA) or breach of service terms claims against security researchers who access systems unintentionally while testing within scope.

Coordinated Public Credit

Unless requested otherwise, we credit security researchers on our official Hall of Fame once a fix is validated and deployed to production.

TARGET MATRIX

Program Scope & Eligibility

Review eligible subdomains, systems, and testing boundaries before conducting research.

Target Asset / PatternTypeSeverity TierStatus
*.example.comAll primary subdomains
Web Apps & APIsCritical - LowFully Eligible
api.example.comCore REST / GraphQL API
Backend APICriticalFully Eligible
auth.example.comSSO & Auth Gateway
AuthenticationCriticalFully Eligible
app.example.comSaaS Customer Portal
Web ApplicationCriticalFully Eligible
Wall of Thanks

Security Researcher Hall of Fame

Honoring the security experts who helped protect our infrastructure, products, and users.

Submit & Get Listed
SR

Samira Rahman

@samirasec
Critical FindingJuly 2026
DC

David Chen

@dchen_hacks
High FindingJune 2026
KP

Kavita Patel

@kavitap_sec
Medium FindingMay 2026
AR

Alex Rivera

@arivera_sec
Critical FindingApril 2026
REPORT VULNERABILITY

Interactive Security Report Builder

Fill out the report details below to automatically format a structured report and draft an email to security@example.com.

Live Formatted Preview
Markdown Auto-Generated
# [SECURITY REPORT] Vulnerability Report Summary

**Target Asset:** https://api.example.com/endpoint
**Category:** Vulnerability Finding
**Severity:** P3 - Medium
**Reporter:** Security Researcher (researcher@example.com)
**Hall of Fame Credit:** Yes (Handle: Anonymous)
**Date:** 2026-07-30

---

### 1. Vulnerability Description & Steps to Reproduce
1. Step one to reproduce...\n2. Step two...

### 2. Impact & Suggested Remediation
Impact details and suggested fixes.

---
*Submitted via Responsible Disclosure Portal.*