Terravek runs a coordinated vulnerability disclosure programme. No bounty, no legal threats, a 72-hour acknowledgement commitment and credit where the researcher wants it. Here is last year's data.

Thirty-one reports. Nine were duplicates of reports already in progress. Eleven were out of scope — mostly findings against third-party services on our domain, or reports of missing headers with no demonstrated impact. Eight were valid and fixed. Three were valid, accepted as risk, and documented with the reasoning shared back to the reporter.

Median time to first response was 11 hours against our 72-hour commitment. Median time to fix for the eight valid findings was 19 days. The slowest was 94 days and involved a third-party dependency; we told the reporter that at day 20 rather than letting it go quiet, which is the part I care about most.

The three risk-accepted findings are the interesting category. In each case the reporter disagreed with us initially, and in one case they changed our mind and we fixed it after all. That exchange only happens if researchers believe the response is written by an engineer rather than a lawyer.

Our policy is at /.well-known/security.txt and /legal/vulnerability-disclosure.html. We do not require an NDA and we will not ask you to sign one.