> ## Content Index
> Fetch the complete content index at: https://cje.io/llms.txt
> Use this file to discover other available public pages before exploring further.

# disclose.io — Driving safety, simplicity, and standardization in vulnerability disclosure.
- URL: https://cje.io/2014/07/23/disclose-io-driving-safety-simplicity-and-standardization-in-vulnerability-disclosure/
- Published: 2014-07-23T00:00:00.000Z
- Updated: 2026-04-04T04:24:32.000Z
- Author: Casey Ellis
- Tags: vulnerability-disclosure, #disclose-io, Security

[disclose.io](https://disclose.io/?ref=cje.io) is a collaborative and vendor-agnostic project to standardize best practices around safe harbour for good-faith security research.

The project expands on the work done by Bugcrowd and CipherLaw’s [Open Source Vulnerability Disclosure Framework](https://github.com/bugcrowd/disclosure-policy?ref=cje.io), Amit Elazari’s [#legalbugbounty](https://github.com/EdOverflow/legal-bug-bounty?ref=cje.io), and Dropbox’s [call to protect security researchers](https://blogs.dropbox.com/tech/2018/03/protecting-security-researchers/?ref=cje.io).

Our framework is designed to balance:

- Legal completeness
- Safe harbor for researchers
- Safe harbor for program owners
- Readability… For those without a legal background or who don’t speak English as their first language. In short, everyone.

Organizations displaying the disclose.io logo are committing to a set of [core terms](https://github.com/disclose/disclose/blob/master/core%5Fterms?ref=cje.io) focused on creating safe harbor for good-faith security research.

In order to uphold this commitment, such organizations are required to provide:

- Clear definitions regarding the permitted Scope.
- One or more Official Communication Channels.
- A formal Disclosure Policy.