Home / Services / Vulnerability Disclosure Program
Advisory · Service

Vulnerability Disclosure Program — VDP · bug-bounty program

Stand up a Vulnerability Disclosure Program (VDP) or bug-bounty — policy definition, triage process, researcher communications and reward management.

Scope this engagement See related tools
ISO 29147ISO 30111CERT/CC Guidelines
What's tested

Coverage that goes deep.

Stand up a Vulnerability Disclosure Program (VDP) or bug-bounty — policy definition, triage process, researcher communications and reward management.

  • VDP policy & scope definition
  • Researcher portal setup
  • Triage process & SLA
  • Severity scoring (CVSS v3.1)
  • Reward / bounty management
  • Public disclosure coordination
  • Hall of fame / acknowledgement system
§ ENGAGEMENT SNAPSHOT
Timeline
3–6 weeks setup
Methodology
ISO 29147
ISO 30111
CERT/CC Guidelines
Category
Advisory
Re-test
Included after fixes

Every engagement is led by a CRTO/OSCP-certified senior engineer with named accountability.

Deliverables

What you get back.

A structured deliverable pack you can hand to engineers, auditors and the board.

DELIVERABLE 01

VDP policy document

DELIVERABLE 02

Triage runbook

DELIVERABLE 03

Public disclosure portal

DELIVERABLE 04

Hall-of-fame management

Methodology

How we work.

PHASE 01

Scope

Confidential scoping call. We agree assets, environments, exclusions and timing.

PHASE 02

Test

Active testing per agreed methodology, with daily check-ins on critical findings.

PHASE 03

Report

Executive + technical deliverables. CXO presentation if you want it.

PHASE 04

Retest

Re-test included after your team applies fixes. Certificate issued on pass.

FAQ

Common questions.

VDP vs bug bounty?
A VDP has no monetary reward and is typically broader. A bug bounty pays researchers and is usually scoped tightly.
Scope this engagement

Tell us about your environment.

A 30-minute scoping call — confidential, NDA-protected, complimentary. Our senior security team will respond within 4 business hours.

  • Named senior engineer on every project
  • In-house tools in production · ISO 27001 aligned practices
  • 4-hour breach SLA · 5–10 day delivery