Skip to main content

Vulnerability Disclosure Policy on YesWeHack

Explore the different use cases and solutions for your VDP

Updated over a week ago

Why should you implement a Vulnerability Disclosure Policy?

A Vulnerability Disclosure Policy (VDP) provides a secure, anonymous, and straightforward way for anyone to report potential security vulnerabilities to your organisation.

Unlike active security testing, a VDP is a passive approach — it creates an open channel for external parties, such as security researchers or even customers who stumble upon sensitive data, to report issues responsibly and legally.

By encouraging early and legal disclosure, a VDP helps organisations identify and fix vulnerabilities before malicious actors ("black hats") can exploit them.

ℹ️ There should be no incentive or expectation of financial rewards for reporting vulnerabilities. VDP is a complementary approach to bug bounty.

A VDP is advocated by regulatory agencies such as NIST, ENISA and CISA and prescribed through standards ISO 29147 and ISO 30111.

Key benefits

  • Reduce the risk of public disclosures and minimise time to detection and remediation.

  • Ensure information confidentiality thanks to end-to-end encrypted communication with researchers.

  • Offer a legal and public way to report vulnerabilities and convince researchers who may hesitate to disclose issues due to fears of legal repercussions.

  • Manage all incoming reports through a single and intuitive interface.

  • Demonstrate your organisation’s dedication to cybersecurity and build trust with customers and other stakeholders. It guarantees researchers that their findings will be taken seriously and handled appropriately.

  • Stay ahead of regulatory requirements.


YesWeHack VDP solutions

ℹ️ You must be a Business Unit Owner or a Business Unit Manager to create a VDP on the YesWeHack platform.

YesWeHack provides three VDP solutions on the platform, designed to suit your organisation’s needs:

  • Standard VDP

  • Embedded VDP

  • Featured VDP

Standard VDP

Set up your own VDP on a dedicated webpage hosted on YesWeHack. Here’s an example of our own VDP.

Learn more about this format and how to create it here.

Embedded VDP

Embedd your VDP in an iframe to be displayed on a webpage of your choice.

Learn more about this format and how to set it up here.

Featured VDP

Showcase your VDP to the YesWeHack hunter community, instead of having it only on specific external webpages.

Learn more about this format and how to set it up here.

ℹ️ Even if a “featured VDP” is accessible to YesWeHack hunters, it is not a Bug Bounty program. These two types of programs should not be confused.

Did this answer your question?