Security Policies Coordinated Disclosure Of Security Vulnerabilities (GitHub)

Updated 10 October 2025

The GitHub Coordinated Disclosure of Security Vulnerabilities and Bug Bounty Program sets out the process for responsibly reporting security issues and the rewards available for verified findings. It is part of GitHub’s official security framework, backed by a clear Legal Safe Harbor Policy and trusted as a leading industry standard for researcher engagement.

Coordinated Disclosure of Security Vulnerabilities

We want to keep [company name] safe for everyone. If you've discovered a security vulnerability in [company name], we appreciate your help in disclosing it to us in a coordinated manner.

Bounty Program

Like several other large software companies, [company name] provides a bug bounty to better engage with security researchers. The idea is simple: hackers and security researchers (like you) find and report vulnerabilities through our coordinated disclosure process. Then, to recognize the significant effort that these researchers often put forth when hunting down bugs, we reward them with some cold hard cash.

Check out the [company name] [site link] for bounty details, review our comprehensive [legal safe harbor policy link] terms as well, and happy hunting!

About this template

What is this template?

Security Policies Coordinated Disclosure Of Security Vulnerabilities (GitHub) is a free, ready-to-use Cybersecurity template you can open, customize, and download on GitLaw. It gives you a professionally structured starting point, so you never have to draft from a blank page. The wording is plain and modern, organized into clear sections that are easy to read, edit, and adapt to your own situation before you share or sign it.

When should you use it?

Reach for this Cybersecurity template whenever you need a reliable agreement quickly and want to be sure the essentials are covered. It suits individuals, freelancers, startups, and established businesses alike. Instead of paying for a document drafted from scratch, you can start here, tailor the details to your arrangement, and have a polished draft ready in minutes. This version is drafted with United States of America in mind, though you should always review the final wording against the laws that apply to you.

What's typically included?

A well-drafted Cybersecurity usually sets out the parties involved, the scope of the agreement, and each side's rights and responsibilities. Expect sections covering key terms and definitions, how long the agreement lasts, how it can be ended, and what happens if something goes wrong. This template brings those building blocks together in a sensible order, so you can focus on the specifics rather than worrying about what to include. Open it to read the full document, then sign up to edit, negotiate, and e-sign it directly in GitLaw.

Jurisdiction
United States of America
Source
G
Security Policies Coordinated Disclosure Of Security Vulnerabilities (GitHub)
from GitHub
Document info
HTML document. Document created on Mon Oct 6th, 2025. Last updated on Fri Oct 10th, 2025.
This document is public
Licensed under CC BY 4.0 (Attribution).
Come to agreements faster
Write, review, negotiate, and manage legal contracts
Related documents
OLOpen Legal Library
Pocket Privacy Policy by Mozilla
OLOpen Legal Library
Cell Phone Policy by EasyLegalDocs
OLOpen Legal Library
Sample Code of Conduct Policy (NVCA)
OLOpen Legal Library
Anti-Bribery and Corruption Policy by EasyLegalDocs
OLOpen Legal Library
Privacy Policy by EasyLegalDocs
OLOpen Legal Library
Anti Slavery Policy by EasyLegalDocs