This document outlines the legal safe harbor terms for security researchers participating in the GitHub Bug Bounty Program. It assures researchers that GitHub will not pursue civil or criminal action for good faith policy violations and details how information is shared with affected third parties. The policy also provides a limited waiver for certain site policy restrictions to facilitate security research.