You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Disclosure enables you to be transparent about the security vulnerabilities found for your program. HackerOne's disclosure process balances transparency with control over what information is shared with the public.
8
18
9
19
Programs can choose from 3 disclosure settings:
@@ -14,7 +24,17 @@ Disclosure by Default | The hacker or your security team can request disclosure
14
24
Disclosure requiring Mutual Agreement | The hacker can request disclosure for any closed report in your program. If your program security team agrees to disclosure, the contents of the report will be made public. If the security team doesn't take any action, the contents of the report will remain private. <br><br>*You must request to opt-in to this option.*
15
25
Disclosure Disabled | Disclosure isn't allowed for any report.
16
26
17
-
### Requesting Disclosure
27
+
<divclass="background contents"markdown="1">
28
+
29
+
In this article, you can learn about:
30
+
----------------------------------- |
31
+
[Requesting Disclosure](#requesting) |
32
+
[Canceling Disclosure Requests](#canceling) |
33
+
[Disclosure for Private Programs](#disclosure) |
34
+
</div>
35
+
36
+
<h3id="requesting">Requesting Disclosure</h3>
37
+
18
38
Both hackers and program members can request for disclosure. To request for disclosure:
19
39
1. Go to the report you want to disclose.
20
40
2. Make sure the report is closed.
@@ -37,7 +57,8 @@ After disclosure has been requested, the admin of the of the program can choose
You can cancel your disclosure request if you later decide to not disclose your report. You can also cancel disclosure requests from hackers asking you for disclosure.
42
63
43
64
To cancel a disclosure request:
@@ -49,7 +70,8 @@ To cancel a disclosure request:
49
70
3. Enter a comment explaining why you are canceling the disclosure request.
50
71
4. Click **Post**.
51
72
52
-
### Disclosure for Private Programs
73
+
<h3id="disclosure">Disclosure for Private Programs</h3>
74
+
53
75
If you’re running a private program, you can enable hackers to disclose a report within your private program. Upon disclosure, contents of the report will only be visible to participants in your private program. This enables hackers to share their vulnerability findings with other hackers in the program, and can also increase awareness for other hackers as they can better see what vulnerabilities have already been found for your program.
0 commit comments