This document outlines the legal safe harbor policy for security researchers participating in GitHub's bug bounty program. It assures researchers that GitHub will not pursue legal action for good faith security research and details how researcher information is handled when third parties are involved. The policy aims to encourage coordinated disclosure of vulnerabilities without fear of legal consequences.