Responsible Disclosure is the public policy for reporting a vulnerability in the Sigvex platform. It says plainly what’s in scope, where to send a report, what a reporter can expect back, and how the program treats good-faith research — published openly so a researcher doesn’t have to ask first.
Why it exists
Responsible disclosure only works when the rules are unambiguous. A researcher needs to know, before they start, what’s fair game, where the report goes, and that acting in good faith won’t be held against them. This page is that policy, public so it can be read without a sign-in.
Who uses it
- Security researcher — reads the policy before submitting a report.
- Legal reviewer — checks the scope and safe-harbour language.
What’s on the page
The policy is organized so you can find what you need: an introduction and a scope section (what’s in and out of bounds), how to report, what to expect and the disclosure timeline, the safe-harbour terms for good-faith research, recognition for reporters, what the program asks of you in return, and a contact for anything else.
Limits
- It’s a public, read-only page — no sign-in required.
- Submitting a report goes through the contact channel described in the policy, not through this page.
Related pages
- Security at Sigvex — the platform security page that links here.
- Forensic Provenance Ledger — anchor a report artifact for reproducibility.