Security Policies Github Bug Bounty Program Legal Safe Harbor (GitHub)
The GitHub Bug Bounty Program Legal Safe Harbor sets out legal protections for security researchers who act in good faith when reporting vulnerabilities through GitHub’s bug bounty program, ensuring their work is treated as “authorized” under laws like the CFAA and DMCA. It is part of GitHub’s official security policies, providing researchers confidence and trust that responsible disclosure will not expose them to legal consequences when complying with program rules.
[company name] Bug Bounty Program Legal Safe Harbor
Summary
We want you to coordinate disclosure through our bug bounty program, and don't want researchers put in fear of legal consequences because of their good faith attempts to comply with our bug bounty policy. We cannot bind any third party, so do not assume this protection extends to any third party. If in doubt, ask us before engaging in any specific action you think might go outside the bounds of our policy.
Because both identifying and non-identifying information can put a researcher at risk, we limit what we share with third parties. We may provide non-identifying substantive information from your report to an affected third party, but only after notifying you and receiving a commitment that the third party will not pursue legal action against you. We will only share identifying information (name, email address, phone number, etc.) with a third party if you give your written permission.
If your security research as part of the bug bounty program violates certain restrictions in our site policies, the safe harbor terms permit a limited exemption.
Safe Harbor Terms
To encourage research and coordinated disclosure of security vulnerabilities, we will not pursue civil or criminal action, or send notice to law enforcement for accidental or good faith violations of this policy. We consider security research and vulnerability disclosure activities conducted consistent with this policy to be “authorized” conduct under the Computer Fraud and Abuse Act, the DMCA, and other applicable computer use laws such as Cal. Penal Code 502(c). We waive any potential DMCA claim against you for circumventing the technological measures we have used to protect the applications in this bug bounty program's scope.
Please understand that if your security research involves the networks, systems, information, applications, products, or services of a third party (which is not us), we cannot bind that third party, and they may pursue legal action or law enforcement notice. We cannot and do not authorize security research in the name of other entities, and cannot in any way offer to defend, indemnify, or otherwise protect you from any third party action based on your actions.
You are expected, as always, to comply with all laws applicable to you, and not to disrupt or compromise any data beyond what this bug bounty program permits.
Please contact us before engaging in conduct that may be inconsistent with or unaddressed by this policy. We reserve the sole right to make the determination of whether a violation of this policy is accidental or in good faith, and proactive contact to us before engaging in any action is a significant factor in that decision. If in doubt, ask us first!
Third Party Safe Harbor
This is a preview. The full template is free on GitLaw.
5.0 out of 5 on Google
Read reviewsAs seen in








About this template
What is this template?
This is a public legal policy governing the relationship between a platform and security researchers. It is not an employment contract or a payment schedule. It specifically grants a limited exemption for activities that might otherwise violate the DMCA or California Penal Code 502(c).
When should you use it?
Use this policy when establishing the legal boundaries of a bug bounty program to encourage ethical hacking without fear of prosecution. Use a standard Terms of Service instead for general platform usage rules.
What's inside
| Clause | Name | What it does |
|---|---|---|
| 1 | Safe Harbor Terms | The company waives civil or criminal claims and DMCA actions against researchers conducting vulnerability disclosure consistent with the Computer Fraud and Abuse Act. |
| 2 | Third Party Safe Harbor | The company restricts sharing a researcher's identifying information with third parties until receiving a written commitment not to pursue legal action. |
| 3 | Limited Waiver of Other Site Policies | Company site policy restrictions are waived specifically to permit security research activities that remain consistent with bug bounty program terms. |
Who it's for
- a company managing a bug bounty program specifically involving security research on their digital applications
- security researchers seeking legal protection from criminal or civil prosecution for accidental violations of site policies
- an organization defining the extent of its duty to defend researchers against third-party law enforcement notices
Law it's drafted under
United States note
This version is drafted for US law generally. Contract, employment and consumer rules vary by state — for example on non-competes and at-will employment. Tell GitLaw which state applies and it adjusts the draft.
Frequently asked questions
A template isn't binding on its own - like any contract, it becomes binding once it's properly completed and signed. Templates in our curated library are professionally drafted for US or UK law; review any template before you sign it.
Yes. Chat with GitLaw to edit any section, or make changes directly in the editor.
Yes, read about team plans here.
Describe what you need in the chat and GitLaw will draft it for you.
Templates in our curated library are professionally drafted for US or UK law. The wider library comes from the GitLaw community and public sources - a solid starting point, but check any template fits your situation before you rely on it.
Mostly US and UK law. Some templates use general commercial terms that work across jurisdictions, and many note which law they're written for.
It depends on the situation. Templates work well for routine business agreements. For anything involving significant money, complex IP, employment, or areas you're unsure about, it's worth getting professional advice before you sign. GitLaw provides templates and tools, not legal advice.
Open any template in GitLaw and describe the change you want in the chat — 'make clause 4 mutual' or 'add a 30-day notice period', for example. GitLaw drafts the revised language and shows it as a suggested edit. You accept, reject, or keep editing from there.
Yes. Upload a Word, PDF, or Markdown file and GitLaw will open it in the editor. You can review, edit, or chat with GitLaw about it the same way you would with any template from the library.
Trusted by 5,000+ businesses


From template to signed, in one place
Every template opens in an editor with an AI agent alongside it.
Open
Pick a template and open it. Nothing to download, and no credit card to start.
Free to open
Edit with AI
Describe your situation in chat and the agent adapts the wording, clause by clause.
Tracked changes you can review
Send and sign
Share it for negotiation, then collect signatures without leaving GitLaw.
eSign included
Built for your legal work,
with practicing lawyers
Trained on 5,500+ clauses and specialist areas of law. Built with a standards committee of independent lawyers.
As seen in








Ready to get started?
No sales calls, no credit card. Just chat with GitLaw.
GitLaw provides templates and tools, not legal advice. Templates are a starting point, not a substitute for advice on your situation - for anything significant, speak to a qualified lawyer.



