How to Set Up a Vulnerability Disclosure Program

White Paper Banner

Leaked secrets get found by outsiders. GitGuardian's research team discloses critical secret leaks to companies year-round, and only about half of those disclosures end in proper remediation. Often missing is a reliable path to someone with the authority to revoke the credential.

This guide gives security leaders six practical steps to build that path: an internal secrets-leak playbook, a security.txt file and monitored security@ address, a vulnerability disclosure policy with safe-harbor language, a bug bounty that routes ineligible reports instead of closing them, and an end-to-end test of the channel. Each step ends with a secrets test you can run this week.

Get the guide

A warning has to reach someone who can act

‍

By submitting this form, I agree to GitGuardian’s Privacy Policy

Thank you! You will soon receive the white paper in your email.
Oops! Something went wrong while submitting the form.

Leaked secrets get found by outsiders. GitGuardian's research team discloses critical secret leaks to companies year-round, and only about half of those disclosures end in proper remediation. Often missing is a reliable path to someone with the authority to revoke the credential.

This guide gives security leaders six practical steps to build that path: an internal secrets-leak playbook, a security.txt file and monitored security@ address, a vulnerability disclosure policy with safe-harbor language, a bug bounty that routes ineligible reports instead of closing them, and an end-to-end test of the channel. Each step ends with a secrets test you can run this week.

A warning has to reach someone who can act

‍

Download now

Trusted by security leaders at the world’s largest companies

Summary

Give leaked-secret reports a path to the right team

Bug bounty programs are selective by design. Reports that fall outside their scope or land with a platform triager can be closed before anyone on the security team sees them. Leaked credentials hit every one of those failure modes.

The fix is a disclosure channel: an easy-to-find reporting path, a policy that accepts out-of-scope and anonymous reports, and an internal playbook that can revoke a credential rather than just delete it.

In this guide, you'll learn:

  • What a disclosure channel is
  • The five failure modes GitGuardian researchers hit when reporting leaked credentials through bounty programs
  • How to build a six-move secrets-leak playbook
  • What a comprehensive disclosure policy requires
White Paper Banner
White paper page preview
Left arrow
Right arrow