ThreatDown Responsible Disclosure Guidelines

Verantwortungsvolle vs. unverantwortliche Offenlegung

Nach unserer Erfahrung stellen (a) die Offenlegung von Proof-of-Concept-Exploit-Code, (b) unnötige Details zur Veranschaulichung des Problems oder (c) die Veröffentlichung von Details zu Sicherheitslücken vor der Verfügbarkeit eines Fixes eine unverantwortliche Offenlegung dar, die mehr Schaden als Nutzen bringt, da sie unnötige Aufmerksamkeit auf ein Sicherheitsproblem lenkt. Daher vergibt das ThreatDown nur Bug-Bounties an Melder, die sich an die Richtlinien für verantwortungsvolle Offenlegung halten.

What do we mean by Responsible Disclosure Program ?

A vulnerability disclosure program (VDP), also known as a responsible disclosure program, offers a structured and responsible channel that researchers can use for submitting accidental security vulnerability findings across our entire ecosystem of applications, infrastructure, services and products.

Reports submitted through ThreatDown’s Responsible Disclose Program are not eligible for monetary awards. However, when applicable, we can request CVEs, and ThreatDown will provide recognition. 

What do we mean by Bug Bounty Program?

A bug bounty program engages researchers to look for vulnerabilities within ThreatDowns’s products in scope in exchange for a monetary award.

ThreatDown Geldprämien für die interessantesten Bugs. Die Höhe der Prämie für interessante Bugs hängt vom Schweregrad und der Ausnutzbarkeit des Bugs ab. ThreatDown jedoch das Recht ThreatDown , diesen Betrag von Fall zu Fall zu erhöhen.

Welche Vertraulichkeitsverpflichtungen gehe ich mit der Einreichung ein?

If you send us a submission for our programs, you are agreeing that you will never disclose functioning exploit code (including binaries of that code) for the applicable vulnerability to any other entity, unless ThreatDown makes that code generally publicly available or agrees on the disclosure after resolution or you are required by law to disclose it. This does not prevent you from discussing the vulnerability or showing the effects of the exploit in code.

Welche Arten von Schwachstellen akzeptiert das CVD-Programm?

Our public bug bounty program accepts vulnerability reports for the targets within the ThreatDown’s program scope. Please follow our program guidelines on the HackerOne platform.

Our responsible disclosure program accepts reports about vulnerabilities from any ThreatDown website, service or product.

Last edited September 15, 2026