Disclose.io
Disclose.io is a San Francisco-based non-profit open-source project that standardizes vulnerability disclosure programs and safe-harbor protections for security researchers. It provides free policy templates, a six-level maturity model, a directory of 27,583+ VDPs, and lookup tooling to organizations, researchers, legal teams, and policymakers globally.
- Company typePrivate
- Founded2018
- HeadquartersSan Francisco, United States
- Headcount1–10
- GTM typeB2B
- OfferingSoftware
What Disclose.io does
Disclose.io is a San Francisco-based non-profit, open-source collaborative project founded in August 2018 to standardize vulnerability disclosure programs (VDPs) and promote safe-harbor protections for security researchers. It was formed from the merger of separate standardization initiatives started by RainForest Puppy, Bugcrowd, Cipherlaw, Dropbox, Dr. Amit Elazari, UC Berkeley, the US Department of Justice, and others, and is currently in the process of incorporating as a 501(c)(3). The project's product suite includes Policymaker (a free policy generator), a Directory of 27,583+ known VDP and bug bounty programs, lookup.disclose.io (a universal security contact lookup tool currently in beta with API-first and MCP-driven architecture), the disclose.io/threats archive of legal threats against researchers, the dioterms CC0 1.0-licensed policy templates, and the diostatus six-level maturity model (Level 0 Not Present through Level 5 Full Safe Harbor + CVD). Supporting resources include a Discourse-based community forum, the "Running With Scissors" blog, the weekly Policy Pulse newsletter, and the Platforms Directory cataloging bug bounty platforms globally.
The underlying technology is an open-source policy standardization framework rather than a single product. The directory's value is driven by network effects: more programs listed attract more researchers, which incentivizes more organizations to publish their VDP. Disclose.io's templates, maturity model, and lookup infrastructure have been aligned with or cited by multiple regulatory frameworks including EU Cyber Resilience Act, EU NIS2, UK PSTI Act, CISA BOD 20-01, NIST SP 800-216, and RFC 9116 (security.txt), positioning the project as a de facto implementation standard for mandated vulnerability disclosure.
The business model is explicitly non-commercial. All tools, templates, and resources are provided free of charge under a CC0 1.0 license with no paid tiers. The organization has no venture capital or equity investment on record, is funded through community contributions, and does not generate revenue from platform fees, licensing, or services. Its go-to-market motion is product-led and community-led, with self-serve adoption via the website, GitHub, and community forum, supplemented by conference talks, the Hackers on the Hill advocacy initiative, and partnerships with the Security Research Legal Defense Fund, The Hacking Games, and I Am The Cavalry.
Disclose.io firmographics
Firmographics- Name
- Disclose.io
- Legal name
- disclose.io
- Website
- https://disclose.io
- Company type
- Private
- Founded year
- 2018
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- Disclose.io is a San Francisco-based non-profit open-source project that standardizes vulnerability disclosure programs and safe-harbor protections for security researchers. It provides free policy templates, a six-level maturity model, a directory of 27,583+ VDPs, and lookup tooling to organizations, researchers, legal teams, and policymakers globally.
- Ownership category
- akta.pro rank
Disclose.io industry classification
Industry- Product category
- Vulnerability Disclosure Management
- NAICS
- Security Systems Services (56162)
- akta.pro primary industry
- Secrets Management & Credential Security (HDADACAH)
Keywords
Where Disclose.io is headquartered
LocationHeadquarters
- HQ city
- San Francisco
- HQ country
- United States
- HQ region
- North America
Markets served
Disclose.io business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations, Infrastructure
Revenue model
- Non-commercial / Open Source: Disclose.io operates as a non-profit project with all tools and resources made freely available. The organization is currently pursuing 501(c)(3) tax-exempt status and was formed as a merge of separate standardization projects initiated by RainForest Puppy, Bugcrowd, Cipherlaw, Dropbox, Dr. Amit Elazari, UC Berkeley, and others. No commercial revenue model is described; the project relies on community contribution and is not designed for commercial profit.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Others | Free tier - All tools and resources available at no cost |
Go-to-market motion2 records
Distribution channels3 records
Marketing channels7 records
Disclose.io product offering
Product offeringCore offering
Disclose.io provides open-source, public-domain (CC0 1.0) vulnerability disclosure policy templates, a six-level VDP maturity model (diostatus), and a suite of free self-serve tools — including Policymaker (policy generator), Directory (27,583+ indexed VDPs/bug bounty programs), Lookup (security contact lookup), Threats Archive (legal threats against researchers), and a Community Forum — to help organizations launch compliant vulnerability disclosure programs and to help security researchers find safe-harbored programs.
Product overview
Disclose.io is a collaborative, vendor-agnostic open-source project that standardizes vulnerability disclosure best practices and safe harbor for security researchers. The platform operates as a suite of interconnected tools: Policymaker generates compliant VDP and bug bounty policies; Directory (27,583+ programs) and Lookup provide program discovery and contact lookup; Threats Archive documents legal risks to researchers; and the Community Forum facilitates collaboration. The dioterms open-source framework provides CC0-licensed policy templates, while the diostatus Maturity Model provides a six-level assessment framework for program quality. Additional offerings include the Platforms Directory (bug bounty platform registry), Policy Pulse newsletter, and Upcoming Dates calendar.
Differentiator
Problem solved
Functional benefit
Brands
- dioterms: The open-source vulnerability disclosure policy template project
- diostatus
- Policy Maker
- Policymaker
- Disclose.io Directory
- lookup.disclose.io
- disclose.io/threats
- Policy Pulse
- Running With Scissors
Products and services
- Policymaker A free, open-source policy generator at policymaker.disclose.io that organizations use to build compliant vulnerability disclosure policies (VDPs) and bug bounty program policies, including safe harbor language, security.txt, and disclosure timelines.
- Directory
- Lookup A universal security contact lookup tool at lookup.disclose.io that finds bug bounty programs, security.txt files, and VDP contacts for any digital asset; currently in beta with API-first and MCP-driven architecture in development.
- Threats Archive A structured public archive at disclose.io/threats of legal threats, cease-and-desist letters, and prosecutions against security researchers engaged in good-faith vulnerability disclosure, documenting date, entity, researcher, topic, and case status.
- Community Forum A Discourse-based community forum at community.disclose.io where security researchers, policymakers, lawyers, and technology vendors collaborate on disclosure practices and contribute to the project.
- dioterms (VDP Policy Templates) Open-source vulnerability disclosure policy templates licensed CC0 1.0, including VDP, Bug Bounty Program (BBP), and Safe Harbor terms, with modular design for legal translation.
- diostatus Maturity Model A six-level self-assessment model describing how prepared an organization is to receive and handle external vulnerability reports: Level 0 (Not Present), Level 1 (Contact Only), Level 2 (Basic VDP), Level 3 (Partial Safe Harbor), Level 4 (Full Safe Harbor), Level 5 (Full Safe Harbor + CVD).
- Platforms Directory A community-maintained vendor-agnostic list of every bug bounty and vulnerability disclosure platform known globally, including regional and vertical-specific platforms.
Quantifiable outcome
- 27,583+ vulnerability disclosure programs indexed in the directory
- +1 more outcomes
Companies that use Disclose.io
Customer profileSegments4 records
Ideal customer profiles4 records
Disclose.io technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature6 records
Disclose.io partnerships and signals
Strategic signalPartnerships
Three partnerships are on record, tiered core.
- Security Research Legal Defense Fund (SRLDF)coreA 501(c)(3) nonprofit that helps fund legal representation for security researchers who face legal threats as a result of good-faith security research. SRLDF accepts applications for defense grants from researchers facing legal action and accepts tax-deductible donations. Both organizations share the mission of protecting security researchers from legal threats.
- The Hacking GamescoreA community and pipeline that helps unconventional thinkers — gamers, CTF players, and bug bounty hunters — turn their talents into legitimate cybersecurity careers. Provides Discord community and partnership opportunities for organizations wanting to hire outside the traditional pipeline.
- Hackers on the HillcoreAn I Am The Cavalry initiative that brings security researchers face-to-face with policymakers. Founded in 2017 and now global. 2026 events run in Den Haag (May 8) and Washington DC (June 16), with a new state-capitol pilot in Denver. Supports researcher-policymaker dialogue on security disclosure policy.
Scale indicators5 records
Recent moves6 records
Expansion highlights5 records
Disclose.io competitors and assessment
Company assessmentMarket position
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
Disclose.io social profiles
Digital presenceDisclose.io financial estimates
Financial estimateRevenue estimate
Valuation estimate
Disclose.io leadership team
Management profileNumber of profiles
Profiles10 records
Disclose.io funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Disclose.io M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Disclose.io
What does Disclose.io do?
Disclose.io provides open-source, public-domain (CC0 1.0) vulnerability disclosure policy templates, a six-level VDP maturity model (diostatus), and a suite of free self-serve tools — including Policymaker (policy generator), Directory (27,583+ indexed VDPs/bug bounty programs), Lookup (security contact lookup), Threats Archive (legal threats against researchers), and a Community Forum — to help organizations launch compliant vulnerability disclosure programs and to help security researchers find safe-harbored programs.
Is Disclose.io a public or private company?
Disclose.io is a private company. It is classified as nonprofit foundation owned and is currently operating.
When was Disclose.io founded?
Disclose.io was founded in 2018. It employs 1 to 10 people.
Where is Disclose.io based?
Disclose.io is headquartered in San Francisco, United States, in the North America region.
How does Disclose.io make money?
One revenue line is on record: non-commercial / Open Source.
Does Disclose.io have an API?
No public API is recorded for Disclose.io.
What industry is Disclose.io in?
Disclose.io's product category is Vulnerability Disclosure Management. Its primary akta.pro industry code is HDADACAH, Secrets Management & Credential Security. Its NAICS code is 56162.