Security Vulnerability Disclosure Form Template
Collect vulnerability reports from security researchers, including affected systems, reproduction steps, impact, evidence, contact details, and disclosure preferences.
When to use it
- A researcher reports a vulnerability in your product
- You need clear steps to reproduce a security issue
- You want to receive proof files securely
- You need to coordinate disclosure preferences
What it asks
- What is your name?
- What email address can we use to contact you?
- Which system or product is affected?
- What type of vulnerability did you find?
- What steps can we follow to reproduce the issue?
- What could an attacker do by exploiting this issue?
- Upload proof or supporting files
- How would you prefer we handle disclosure?
Why it should be encrypted
Reports may include exploitable details, system information, and proof files that could put users or infrastructure at risk if exposed. Keep access limited to the security staff who need to review the report.
Tips
- Name the products or systems researchers can report issues about.
- Ask reporters not to include real user data or unnecessary secrets in proof files.
- Explain how your team will follow up and handle disclosure requests.