Presenting disclosure, A federated and liberated bug bounty and vulnerability disclosure platform. Security researchers and companies communicate directly — no middleman, no platform fees, no gatekeepers. Researchers disclose vulnerabilities on their own terms. Companies run bug bounty programs on their own servers. They find each other through federation.
No reviews yetBe the first to leave a review for DISCLOSURE
Maker
📌
Current bug bounty platforms are centralized. They sit between researchers and vendors, controlling access, mediating communication, and holding all the data. Researchers often face gatekeeping. Vendors can't run programs without paying a cut. Then there are vendors who run their own programs but lose visibility and access to the pool of researchers. With recent development in AI, researchers also fear their work might be used for training models while vendors are being flooded with lots of noise. Researchers are being exploited and companies are being looted. The deals are unfair for both and the middleman is profiting in between.
I had to do something about it, so I built Disclosure to liberate security research from the hands of the middle man. Disclosure is for security researchers and vendors alike. Both parties get full ownership with no middle man. Being a self hosted bug bounty platform and a vulnerability disclosure board, disclosure is built to be small, portable and easy to host. Being a federated network, it shares the pool of researchers and bug bounty/vulnerability disclosure programs with everyone, grows with adoption and puts the control back into the hands of its users.
Development is still in early stage, but a basic MVP and the genesis instance can be found at https://whitehat.ivx.run