Harbor

Vulnerability Disclosure Policy

This policy explains how security researchers can report vulnerabilities to participating Harbor organizations in a safe, coordinated, and responsible way.

Purpose

Our goal is to improve security outcomes by giving researchers and organizations a clear process for reporting, triaging, and resolving vulnerabilities.

Authorized Testing

Testing is permitted only on assets explicitly listed as in-scope by each participating program. Out-of-scope systems and techniques are not authorized.

Researcher Expectations

Act in good faith

Avoid privacy violations, disruption, and data exfiltration beyond what is strictly required to demonstrate a vulnerability.

Submit actionable reports

Provide clear reproduction steps, impact details, affected assets, and supporting evidence to speed triage and remediation.

Disclosure Process

Reports should be submitted privately through Harbor. Public disclosure should wait until the organization confirms remediation or provides explicit authorization.

Non-Compliance

Activity that violates scope, law, or policy may result in report rejection, account restrictions, or referral through appropriate legal channels.