Vulnerability Disclosure Policy
This policy explains how security researchers can report vulnerabilities to participating Harbor organizations in a safe, coordinated, and responsible way.
Purpose
Our goal is to improve security outcomes by giving researchers and organizations a clear process for reporting, triaging, and resolving vulnerabilities.
Authorized Testing
Testing is permitted only on assets explicitly listed as in-scope by each participating program. Out-of-scope systems and techniques are not authorized.
Researcher Expectations
Act in good faith
Avoid privacy violations, disruption, and data exfiltration beyond what is strictly required to demonstrate a vulnerability.
Submit actionable reports
Provide clear reproduction steps, impact details, affected assets, and supporting evidence to speed triage and remediation.
Disclosure Process
Reports should be submitted privately through Harbor. Public disclosure should wait until the organization confirms remediation or provides explicit authorization.
Non-Compliance
Activity that violates scope, law, or policy may result in report rejection, account restrictions, or referral through appropriate legal channels.
