Developer docs
API playgroundTry for free, no card

Search company profiles

Disclose.io

Full company profile

uuid0008bdx

Namestring
Disclose.io
Legal namestring
disclose.io
Websiteurl
disclose.io
Company typeenum
Private
Founded yearint
2018
Descriptiontext

Disclose.io is a San Francisco-based non-profit, open-source collaborative project founded in August 2018 to standardize vulnerability disclosure programs (VDPs) and promote safe-harbor protections for security researchers. It was formed from the merger of separate standardization initiatives started by RainForest Puppy, Bugcrowd, Cipherlaw, Dropbox, Dr. Amit Elazari, UC Berkeley, the US Department of Justice, and others, and is currently in the process of incorporating as a 501(c)(3). The project's product suite includes Policymaker (a free policy generator), a Directory of 27,583+ known VDP and bug bounty programs, lookup.disclose.io (a universal security contact lookup tool currently in beta with API-first and MCP-driven architecture), the disclose.io/threats archive of legal threats against researchers, the dioterms CC0 1.0-licensed policy templates, and the diostatus six-level maturity model (Level 0 Not Present through Level 5 Full Safe Harbor + CVD). Supporting resources include a Discourse-based community forum, the "Running With Scissors" blog, the weekly Policy Pulse newsletter, and the Platforms Directory cataloging bug bounty platforms globally.

The underlying technology is an open-source policy standardization framework rather than a single product. The directory's value is driven by network effects: more programs listed attract more researchers, which incentivizes more organizations to publish their VDP. Disclose.io's templates, maturity model, and lookup infrastructure have been aligned with or cited by multiple regulatory frameworks including EU Cyber Resilience Act, EU NIS2, UK PSTI Act, CISA BOD 20-01, NIST SP 800-216, and RFC 9116 (security.txt), positioning the project as a de facto implementation standard for mandated vulnerability disclosure.

The business model is explicitly non-commercial. All tools, templates, and resources are provided free of charge under a CC0 1.0 license with no paid tiers. The organization has no venture capital or equity investment on record, is funded through community contributions, and does not generate revenue from platform fees, licensing, or services. Its go-to-market motion is product-led and community-led, with self-serve adoption via the website, GitHub, and community forum, supplemented by conference talks, the Hackers on the Hill advocacy initiative, and partnerships with the Security Research Legal Defense Fund, The Hacking Games, and I Am The Cavalry.

Short descriptiontext

Disclose.io is a San Francisco-based non-profit open-source project that standardizes vulnerability disclosure programs and safe-harbor protections for security researchers. It provides free policy templates, a six-level maturity model, a directory of 27,583+ VDPs, and lookup tooling to organizations, researchers, legal teams, and policymakers globally.

Operating statusenum
Operating
Ownership categoryenum
Headcount rangeband
1–10
akta.pro rankint
HeadquartersSan Francisco, United States
HQ citystring
San Francisco
HQ countrystring
United States
HQ regionstring
North America
Markets served

Serves global market

Keyword5 values
vulnerability disclosure programs, open-source policy templates, safe harbor framework, bug bounty directory, cybersecurity standardization
Industry1 code
1Secrets Management & Credential Security
CodeHDADACAHPrimaryYes
NAICS code1 code
  • Security Systems Services56162
Product category
Vulnerability Disclosure Management
GTM motion2 records

Each record includes

Type, Description, Source

Revenue model1 record
1Non-commercial / Open Source
TypeFreemium
Description

Disclose.io operates as a non-profit project with all tools and resources made freely available. The organization is currently pursuing 501(c)(3) tax-exempt status and was formed as a merge of separate standardization projects initiated by RainForest Puppy, Bugcrowd, Cipherlaw, Dropbox, Dr. Amit Elazari, UC Berkeley, and others. No commercial revenue model is described; the project relies on community contribution and is not designed for commercial profit.

disclose.io
Marketing channels7 records

Each record includes

Title, Type, Stage, Description, Source

Distribution channels3 records

Each record includes

Title, Type, Scope, Target buyer, Description, Source

Cost components5 values
Personnel, Technology or R&D, Marketing or Sales, Operations, Infrastructure
Pricing details1 tier
1Free tier - All tools and resources available at no cost
ModelFreemiumBilling cadenceOthers
Notes

All disclose.io framework content, Policymaker tool, directory, and lookup tools are provided free of charge. No paid tiers or commercial licensing fees apply.

disclose.io
GTM typeB2B
B2B
Offering typeSoftware
Software
Brand1 of 9 records shown
1dioterms
Description

The open-source vulnerability disclosure policy template project

disclose.io
+8 more records
Core offering1 text field

Disclose.io provides open-source, public-domain (CC0 1.0) vulnerability disclosure policy templates, a six-level VDP maturity model (diostatus), and a suite of free self-serve tools — including Policymaker (policy generator), Directory (27,583+ indexed VDPs/bug bounty programs), Lookup (security contact lookup), Threats Archive (legal threats against researchers), and a Community Forum — to help organizations launch compliant vulnerability disclosure programs and to help security researchers find safe-harbored programs.

Differentiator
Functional benefit
Problem solved
Quantifiable outcome1 of 2 values shown
  • 27,583+ vulnerability disclosure programs indexed in the directory
+1 more record
Product overview1 text field

Disclose.io is a collaborative, vendor-agnostic open-source project that standardizes vulnerability disclosure best practices and safe harbor for security researchers. The platform operates as a suite of interconnected tools: Policymaker generates compliant VDP and bug bounty policies; Directory (27,583+ programs) and Lookup provide program discovery and contact lookup; Threats Archive documents legal risks to researchers; and the Community Forum facilitates collaboration. The dioterms open-source framework provides CC0-licensed policy templates, while the diostatus Maturity Model provides a six-level assessment framework for program quality. Additional offerings include the Platforms Directory (bug bounty platform registry), Policy Pulse newsletter, and Upcoming Dates calendar.

Product and service8 records
1Policymaker
CategoryVulnerability Disclosure Management
Description

A free, open-source policy generator at policymaker.disclose.io that organizations use to build compliant vulnerability disclosure policies (VDPs) and bug bounty program policies, including safe harbor language, security.txt, and disclosure timelines.

2Directory
3Lookup
CategoryVulnerability Disclosure Intelligence
Description

A universal security contact lookup tool at lookup.disclose.io that finds bug bounty programs, security.txt files, and VDP contacts for any digital asset; currently in beta with API-first and MCP-driven architecture in development.

4Threats Archive
CategorySecurity Research Legal Intelligence
Description

A structured public archive at disclose.io/threats of legal threats, cease-and-desist letters, and prosecutions against security researchers engaged in good-faith vulnerability disclosure, documenting date, entity, researcher, topic, and case status.

5Community Forum
CategoryCommunity and Collaboration
Description

A Discourse-based community forum at community.disclose.io where security researchers, policymakers, lawyers, and technology vendors collaborate on disclosure practices and contribute to the project.

6dioterms (VDP Policy Templates)
CategoryOpen-Source Policy Framework
Description

Open-source vulnerability disclosure policy templates licensed CC0 1.0, including VDP, Bug Bounty Program (BBP), and Safe Harbor terms, with modular design for legal translation.

7diostatus Maturity Model
CategoryOpen-Source Policy Framework
Description

A six-level self-assessment model describing how prepared an organization is to receive and handle external vulnerability reports: Level 0 (Not Present), Level 1 (Contact Only), Level 2 (Basic VDP), Level 3 (Partial Safe Harbor), Level 4 (Full Safe Harbor), Level 5 (Full Safe Harbor + CVD).

8Platforms Directory
CategoryVulnerability Disclosure Intelligence
Description

A community-maintained vendor-agnostic list of every bug bounty and vulnerability disclosure platform known globally, including regional and vertical-specific platforms.

Scale indicator5 records

Each record includes

Type, Value, Description, Source

Partnership3 partners
1Security Research Legal Defense Fund (SRLDF)
Strategic tierCoreTypeStrategic or Co-development Partner
Description

A 501(c)(3) nonprofit that helps fund legal representation for security researchers who face legal threats as a result of good-faith security research. SRLDF accepts applications for defense grants from researchers facing legal action and accepts tax-deductible donations. Both organizations share the mission of protecting security researchers from legal threats.

disclose.io
Strategic tierCoreTypeStrategic or Co-development Partner
Description

A community and pipeline that helps unconventional thinkers — gamers, CTF players, and bug bounty hunters — turn their talents into legitimate cybersecurity careers. Provides Discord community and partnership opportunities for organizations wanting to hire outside the traditional pipeline.

Strategic tierCoreTypeStrategic or Co-development Partner
Description

An I Am The Cavalry initiative that brings security researchers face-to-face with policymakers. Founded in 2017 and now global. 2026 events run in Den Haag (May 8) and Washington DC (June 16), with a new state-capitol pilot in Denver. Supports researcher-policymaker dialogue on security disclosure policy.

Recent move6 records

Each record includes

Date, Type, Title, Description, Source

Expansion highlight5 records

Each record includes

Type, Description

Market position
Competitive moat5 records

Each record includes

Type, Details

Key risks6 records

Each record includes

Headline, Details, Source

Key highlights7 records

Each record includes

Headline, Details, Source

Customer concentration

Classification, Details

Segment4 records

Each record includes

Title, Type, Primary, Description, Pain point addressed, Use case, Source

Ideal customer profile4 records

Each record includes

Profile, Firmographic size, Sales motion, Sales cycle length, Buying structure, Purchase trigger, Buyer persona, Geography, Industry vertical, Primary use case, Description, Pain points, Evidence proof points, Target buyer

Technology focused
Yes
API detail
Has APIbool
No

Docs URL, Description

AI maturity
App detail

Has app

Feature6 records

Each record includes

Title, Differentiator, Description, Source

Core technology
Revenue estimate
Valuation estimate
Number of profiles
Profiles10 records

Each record includes

Name, Designation, Designation category, Overview, Profile commentary, Source

No data
No data
Funding overview

Funding stage, Last funding date, Total funding USD

Funding rounds

Each record includes

Round, Amount USD, Date, Pre money valuation, Total investors, Investors, News

Investors

Each record includes

Name, Type, Date of entry, Rounds participated, Website

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

M&A

Each record includes

Name, Acquisition type, Announced date, Completed date, Status, Website, News

Investment

Each record includes

Name, Round, Announced date, Lead investor, Website, News

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Disclose.io

Vulnerability Disclosure Managementdisclose.io

Disclose.io is a San Francisco-based non-profit open-source project that standardizes vulnerability disclosure programs and safe-harbor protections for security researchers. It provides free policy templates, a six-level maturity model, a directory of 27,583+ VDPs, and lookup tooling to organizations, researchers, legal teams, and policymakers globally.

What Disclose.io does

Disclose.io is a San Francisco-based non-profit, open-source collaborative project founded in August 2018 to standardize vulnerability disclosure programs (VDPs) and promote safe-harbor protections for security researchers. It was formed from the merger of separate standardization initiatives started by RainForest Puppy, Bugcrowd, Cipherlaw, Dropbox, Dr. Amit Elazari, UC Berkeley, the US Department of Justice, and others, and is currently in the process of incorporating as a 501(c)(3). The project's product suite includes Policymaker (a free policy generator), a Directory of 27,583+ known VDP and bug bounty programs, lookup.disclose.io (a universal security contact lookup tool currently in beta with API-first and MCP-driven architecture), the disclose.io/threats archive of legal threats against researchers, the dioterms CC0 1.0-licensed policy templates, and the diostatus six-level maturity model (Level 0 Not Present through Level 5 Full Safe Harbor + CVD). Supporting resources include a Discourse-based community forum, the "Running With Scissors" blog, the weekly Policy Pulse newsletter, and the Platforms Directory cataloging bug bounty platforms globally.

The underlying technology is an open-source policy standardization framework rather than a single product. The directory's value is driven by network effects: more programs listed attract more researchers, which incentivizes more organizations to publish their VDP. Disclose.io's templates, maturity model, and lookup infrastructure have been aligned with or cited by multiple regulatory frameworks including EU Cyber Resilience Act, EU NIS2, UK PSTI Act, CISA BOD 20-01, NIST SP 800-216, and RFC 9116 (security.txt), positioning the project as a de facto implementation standard for mandated vulnerability disclosure.

The business model is explicitly non-commercial. All tools, templates, and resources are provided free of charge under a CC0 1.0 license with no paid tiers. The organization has no venture capital or equity investment on record, is funded through community contributions, and does not generate revenue from platform fees, licensing, or services. Its go-to-market motion is product-led and community-led, with self-serve adoption via the website, GitHub, and community forum, supplemented by conference talks, the Hackers on the Hill advocacy initiative, and partnerships with the Security Research Legal Defense Fund, The Hacking Games, and I Am The Cavalry.

Disclose.io firmographics

Firmographics
Name
Disclose.io
Legal name
disclose.io
Website
https://disclose.io
Company type
Private
Founded year
2018
Operating status
Operating
Headcount range
1–10 employees
Short description
Disclose.io is a San Francisco-based non-profit open-source project that standardizes vulnerability disclosure programs and safe-harbor protections for security researchers. It provides free policy templates, a six-level maturity model, a directory of 27,583+ VDPs, and lookup tooling to organizations, researchers, legal teams, and policymakers globally.
Ownership category
akta.pro rank

Disclose.io industry classification

Industry
Product category
Vulnerability Disclosure Management
NAICS
Security Systems Services (56162)
akta.pro primary industry
Secrets Management & Credential Security (HDADACAH)

Keywords

  • Vulnerability disclosure programs
  • Open-source policy templates
  • Safe harbor framework
  • Bug bounty directory
  • Cybersecurity standardization

Where Disclose.io is headquartered

Location

Headquarters

HQ city
San Francisco
HQ country
United States
HQ region
North America

Markets served

Disclose.io business model

Business model
GTM type
B2B
Offering type
Software
Cost components
Personnel, Technology or R&D, Marketing or Sales, Operations, Infrastructure

Revenue model

  1. Non-commercial / Open Source: Disclose.io operates as a non-profit project with all tools and resources made freely available. The organization is currently pursuing 501(c)(3) tax-exempt status and was formed as a merge of separate standardization projects initiated by RainForest Puppy, Bugcrowd, Cipherlaw, Dropbox, Dr. Amit Elazari, UC Berkeley, and others. No commercial revenue model is described; the project relies on community contribution and is not designed for commercial profit.

Pricing tiers

ModelBillingPrice
FreemiumOthersFree tier - All tools and resources available at no cost

Go-to-market motion2 records

Distribution channels3 records

Marketing channels7 records

Disclose.io product offering

Product offering

Core offering

Disclose.io provides open-source, public-domain (CC0 1.0) vulnerability disclosure policy templates, a six-level VDP maturity model (diostatus), and a suite of free self-serve tools — including Policymaker (policy generator), Directory (27,583+ indexed VDPs/bug bounty programs), Lookup (security contact lookup), Threats Archive (legal threats against researchers), and a Community Forum — to help organizations launch compliant vulnerability disclosure programs and to help security researchers find safe-harbored programs.

Product overview

Disclose.io is a collaborative, vendor-agnostic open-source project that standardizes vulnerability disclosure best practices and safe harbor for security researchers. The platform operates as a suite of interconnected tools: Policymaker generates compliant VDP and bug bounty policies; Directory (27,583+ programs) and Lookup provide program discovery and contact lookup; Threats Archive documents legal risks to researchers; and the Community Forum facilitates collaboration. The dioterms open-source framework provides CC0-licensed policy templates, while the diostatus Maturity Model provides a six-level assessment framework for program quality. Additional offerings include the Platforms Directory (bug bounty platform registry), Policy Pulse newsletter, and Upcoming Dates calendar.

Differentiator

Problem solved

Functional benefit

Brands

  • dioterms: The open-source vulnerability disclosure policy template project
  • diostatus
  • Policy Maker
  • Policymaker
  • Disclose.io Directory
  • lookup.disclose.io
  • disclose.io/threats
  • Policy Pulse
  • Running With Scissors

Products and services

  • Policymaker A free, open-source policy generator at policymaker.disclose.io that organizations use to build compliant vulnerability disclosure policies (VDPs) and bug bounty program policies, including safe harbor language, security.txt, and disclosure timelines.
  • Directory
  • Lookup A universal security contact lookup tool at lookup.disclose.io that finds bug bounty programs, security.txt files, and VDP contacts for any digital asset; currently in beta with API-first and MCP-driven architecture in development.
  • Threats Archive A structured public archive at disclose.io/threats of legal threats, cease-and-desist letters, and prosecutions against security researchers engaged in good-faith vulnerability disclosure, documenting date, entity, researcher, topic, and case status.
  • Community Forum A Discourse-based community forum at community.disclose.io where security researchers, policymakers, lawyers, and technology vendors collaborate on disclosure practices and contribute to the project.
  • dioterms (VDP Policy Templates) Open-source vulnerability disclosure policy templates licensed CC0 1.0, including VDP, Bug Bounty Program (BBP), and Safe Harbor terms, with modular design for legal translation.
  • diostatus Maturity Model A six-level self-assessment model describing how prepared an organization is to receive and handle external vulnerability reports: Level 0 (Not Present), Level 1 (Contact Only), Level 2 (Basic VDP), Level 3 (Partial Safe Harbor), Level 4 (Full Safe Harbor), Level 5 (Full Safe Harbor + CVD).
  • Platforms Directory A community-maintained vendor-agnostic list of every bug bounty and vulnerability disclosure platform known globally, including regional and vertical-specific platforms.

Quantifiable outcome

  • 27,583+ vulnerability disclosure programs indexed in the directory
  • +1 more outcomes

Companies that use Disclose.io

Customer profile

Segments4 records

Ideal customer profiles4 records

Disclose.io technology and API

Technology

Technology focussed Yes

API detail

Has API
No
API docs
API detail

Core technology

AI maturity

App detail

Feature6 records

Disclose.io partnerships and signals

Strategic signal

Partnerships

Three partnerships are on record, tiered core.

  • Security Research Legal Defense Fund (SRLDF)coreStrategic or Co-development PartnerA 501(c)(3) nonprofit that helps fund legal representation for security researchers who face legal threats as a result of good-faith security research. SRLDF accepts applications for defense grants from researchers facing legal action and accepts tax-deductible donations. Both organizations share the mission of protecting security researchers from legal threats.
  • The Hacking GamescoreStrategic or Co-development PartnerA community and pipeline that helps unconventional thinkers — gamers, CTF players, and bug bounty hunters — turn their talents into legitimate cybersecurity careers. Provides Discord community and partnership opportunities for organizations wanting to hire outside the traditional pipeline.
  • Hackers on the HillcoreStrategic or Co-development PartnerAn I Am The Cavalry initiative that brings security researchers face-to-face with policymakers. Founded in 2017 and now global. 2026 events run in Den Haag (May 8) and Washington DC (June 16), with a new state-capitol pilot in Denver. Supports researcher-policymaker dialogue on security disclosure policy.

Scale indicators5 records

Recent moves6 records

Expansion highlights5 records

Disclose.io competitors and assessment

Company assessment

Market position

Competitive moat5 records

Key risks6 records

Key highlights7 records

Customer concentration

Disclose.io social profiles

Digital presence

Disclose.io financial estimates

Financial estimate

Revenue estimate

Valuation estimate

Disclose.io leadership team

Management profile

Number of profiles

Profiles10 records

Disclose.io funding detail

Funding detail

Funding overview

Funding rounds

Investors

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

Disclose.io M&A and investment

M&A and investment

M&A

Investments

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Frequently asked questions about Disclose.io

What does Disclose.io do?

Disclose.io provides open-source, public-domain (CC0 1.0) vulnerability disclosure policy templates, a six-level VDP maturity model (diostatus), and a suite of free self-serve tools — including Policymaker (policy generator), Directory (27,583+ indexed VDPs/bug bounty programs), Lookup (security contact lookup), Threats Archive (legal threats against researchers), and a Community Forum — to help organizations launch compliant vulnerability disclosure programs and to help security researchers find safe-harbored programs.

Is Disclose.io a public or private company?

Disclose.io is a private company. It is classified as nonprofit foundation owned and is currently operating.

When was Disclose.io founded?

Disclose.io was founded in 2018. It employs 1 to 10 people.

Where is Disclose.io based?

Disclose.io is headquartered in San Francisco, United States, in the North America region.

How does Disclose.io make money?

One revenue line is on record: non-commercial / Open Source.

Does Disclose.io have an API?

No public API is recorded for Disclose.io.

What industry is Disclose.io in?

Disclose.io's product category is Vulnerability Disclosure Management. Its primary akta.pro industry code is HDADACAH, Secrets Management & Credential Security. Its NAICS code is 56162.

Unlock the full company data

50 free credits on sign-up, no credit card required.

Contact sales