Security Policies Coordinated Disclosure Of Security Vulnerabilities (GitHub)
Updated 17 October 2025
This document outlines GitHub's policy for the coordinated disclosure of security vulnerabilities. It encourages security researchers to report any discovered vulnerabilities to GitHub to help maintain platform safety. The document also introduces GitHub's bug bounty program, which rewards researchers for their efforts in identifying and reporting bugs.
Coordinated Disclosure of Security Vulnerabilities
We want to keep GitHub safe for everyone. If you've discovered a security vulnerability in GitHub, we appreciate your help in disclosing it to us in a coordinated manner.
Bounty Program
Like several other large software companies, GitHub provides a bug bounty to better engage with security researchers. The idea is simple: hackers and security researchers (like you) find and report vulnerabilities through our coordinated disclosure process. Then, to recognize the significant effort that these researchers often put forth when hunting down bugs, we reward them with some cold hard cash.
Check out the GitHub Bug Bounty site for bounty details, review our comprehensive Legal Safe Harbor Policy terms as well, and happy hunting!
About this template
What is this template?
Security Policies Coordinated Disclosure Of Security Vulnerabilities (GitHub) is a free, ready-to-use Cybersecurity template you can open, customize, and download on GitLaw. It gives you a professionally structured starting point, so you never have to draft from a blank page. The wording is plain and modern, organized into clear sections that are easy to read, edit, and adapt to your own situation before you share or sign it.
When should you use it?
Reach for this Cybersecurity template whenever you need a reliable agreement quickly and want to be sure the essentials are covered. It suits individuals, freelancers, startups, and established businesses alike. Instead of paying for a document drafted from scratch, you can start here, tailor the details to your arrangement, and have a polished draft ready in minutes. Always review the final wording against the laws that apply where you live or do business.
What's typically included?
A well-drafted Cybersecurity usually sets out the parties involved, the scope of the agreement, and each side's rights and responsibilities. Expect sections covering key terms and definitions, how long the agreement lasts, how it can be ended, and what happens if something goes wrong. This template brings those building blocks together in a sensible order, so you can focus on the specifics rather than worrying about what to include. Open it to read the full document, then sign up to edit, negotiate, and e-sign it directly in GitLaw.