disclose.io · a sourced history of the terms

The Archeology of Safe Harbor

Where the disclose.io safe-harbor terms actually came from, traced to the earliest located safe-harbor ancestor, with dated primary sources and explicit evidence limits.

Assembled 2026-05-31 Research updated 2026-09-21 Dated sources · explicit evidence limits Confidence-tagged throughout

Earliest provenance root of the dioterms lineage

2014-07-23

first commit of bugcrowd/disclosure-policy, hash 10ea3e1, “first commit,” authored by Chris Raethke (Bugcrowd’s founding CTO) at 23:02:41 −0700.

Precise framing. A “dioterm” is a disclose.io term, and the present terms project launched in 2018. The 2014 artifact is not itself a dioterm, it is the earliest internet-traceable ancestor that the dioterms are directly, repo-documentedly descended from. The claim is about provenance, not the first use of the domain.

That repo’s own GitHub description draws the inheritance explicitly:

“Open Source Vulnerability Disclosure Framework. Maintained by Bugcrowd and Cipherlaw. Merged with github.com/disclose/dioterms.”

The defining feature of dioterms, bilateral safe harbor, is already present in that very first 2014 file (responsible_disclosure_policy.md):

“If you follow these guidelines… we commit to: Not pursue or support any legal action related to your research…”

The dioterms language is therefore ~4 years older than the 2018 terms project it later fed into. Note this proves a Bugcrowd disclosure-policy repo existed in 2014, it does not prove disclose.io was co-founded in 2014 (a separate, bio-sourced claim). Keep those two facts apart.

Why this date is HIGH

  • Author date == committer date (2014-07-23 23:02:41 −0700), the two recorded timestamps agree; both are settable metadata.
  • Root commit, rev-list --parents shows no parent → the root of the history examined; this alone cannot rule out migration or earlier drafts.
  • Clean initial commit, 3 files / 105 insertions (one policy + one guide + README), the scope of this artifact, not independent proof of its creation date.
  • Independent corroboration, the Wayback Machine captured the live repo on 2014-10-16 (HTTP 200) and 2015-03-17, ~3 months after the commit. The dated 2014-07-24 launch release independently corroborates public availability; the archive provides a later observation.

This is a falsifiable claim: it stands until an earlier Bugcrowd template, gist, or snapshot surfaces. The 2026-05-31 refutation hunt found nothing earlier in Bugcrowd’s repos.

Provenance at a glance

2000 RFPolicy early policy 2014 Bugcrowd framework safe-harbor clause 2018 disclose.io merges 3 predecessors 2020 dioterms repo canonical terms '21–'24 parallel legal developments 2026 mission: safe, simple, standardized EARLIEST ROOT
From pre-2014 disclosure norms to the 2014 Bugcrowd root, the 2018 launch, and parallel legal developments. No derivation into law is established.

The lineage chain

Solid lines mark documented inheritance, a repo states it merged something, so that something is a direct ancestor. Dashed lines mark conceptual antecedents: the same problem space, with no sourced derivation.

CONCEPTUAL ANTECEDENTS DOCUMENTED CHAIN 2000 · RFPolicy v1.1 disclosure template 2002 · IETF draft responsible disclosure 2014 · ISO/IEC 29147 vendor-side standard 2014 · Bugcrowd + CipherLaw goodwill safe harbor 2018 · Dropbox “authorized” under CFAA 2018 · Elazari #legalbugbounty standardized template 2018 · disclose.io merges the 3 2020 · dioterms canonical terms Solid = documented inheritance · dashed = conceptual antecedent (no sourced derivation)

The solid chain is sourced: disclose.io’s own 2018 launch page names the three tributaries it merged (Bugcrowd+CipherLaw’s 2014 framework, Elazari’s #legalbugbounty, Dropbox’s researcher-protection language), and bugcrowd/disclosure-policy’s description states it merged into disclose/dioterms. The 2000–2014 norms (RFPolicy, IETF draft, ISO 29147) are dashed: they shaped the problem space of standardized disclosure, but no document shows Bugcrowd’s framework deriving its text from them, antecedents, not parents.

Timeline

Before the templates: coordination, disclosure and rewards

These milestones describe the wider disclosure ecosystem. They do not establish textual ancestry of dioterms.

  • 1988-11

    CERT/CC is established at Carnegie Mellon’s Software Engineering Institute following the Morris worm, creating a center for incident and vulnerability coordination. Source. HIGH

  • by 1993-11-16

    Bugtraq’s surviving archive records discussion of a CERT advisory and an xterm vulnerability. This is evidence of public discussion by that date, not a verified founding date. Source. HIGH

  • 1995-10-10

    Netscape announces its Bugs Bounty program for Navigator 2.0 beta, offering rewards for defects including significant security bugs. An archived copy preserves the original press release. Source. HIGH

  • 1997-05

    RFC 2142 specifies the SECURITY mailbox for security bulletins and queries. RFC 9116 later cites this convention as earlier work on predictable security contacts. Source. HIGH

Timeline

TimelineEach entry: date, milestone, confidence, and source.

Platform pre-history, the crowdsourced-security market (the demand soil)

  • 2012

    Bugcrowd & HackerOne both founded; Bugcrowd launched first. Per HackerOne co-founder/CTO Alex Rice, on record: “Both founded 2012, @Bugcrowd launched first! @Hacker0x01 kickoff 2/2012, 1st commit 4/2012, 1st private 1/2013, 1st public 10/2013.” HIGHCrowdsourced security as a service put researchers and orgs into at-scale engagement, exactly what made standardized safe-harbor terms necessary by 2014.

  • 2013-03-05

    Bugcrowd’s “The List”, earliest Wayback capture of a community-maintained public directory of bug-bounty programs (“Last update: 2nd March 2013”). A functional antecedent of diodb (2018) on the directory axis, conceptual only, no documented derivation. MED

Timeline

Pre-history, disclosure norms (the supply soil)

  • 2000-08 / 10

    RFPolicy v1.1 is archived on 19 August. Rain Forest Puppy announces v2.0 on 17 October: five working days govern initial response and continuing communication, not a patch deadline. Version 2 also removes the earlier non-contract disclaimer. Source. HIGH

  • 2000-10-09

    CERT/CC’s 45-day disclosure policy takes effect, allowing publication without a vendor patch and exceptions for circumstances such as active exploitation. Announced on 3 October. Source. HIGH

  • 2002-02-15

    IETF draft “Responsible Vulnerability Disclosure Process” (Christey/MITRE + Wysopal/@stake), rev 00, an individual proposal that expired without becoming an IETF standard. HIGHGoal: standardize “responsible disclosure” terminology.

  • 2010-07-22

    Microsoft (MSRC) reframes “Responsible Disclosure” → “Coordinated Vulnerability Disclosure.” The neutrality pivot between “responsible” (2002) and the ISO-era vocabulary. HIGHGoal: strip the moral judgment out of the terminology.

  • 2013-11

    ISO/IEC 30111 first edition (vulnerability handling processes), the vendor-internal handling standard, published ~3 months before its better-known sibling ISO/IEC 29147. HIGH

  • 2014-02

    ISO/IEC 29147 first edition (vulnerability disclosure). MEDGoal: a formal international standard.

Timeline

2014, the earliest provenance root (Bugcrowd precursor, not yet a “dioterm”)

  • 2014-03-31

    Bugcrowd “Standard Disclosure Terms”, platform-wide terms for its programs (in-page changelog: “Initial Release”), carrying researcher-protection intent (“the more closely your behavior follows these rules, the more we’ll be able to protect you”) but no legal safe-harbor clause. An earlier Bugcrowd terms artifact, not the provenance root. HIGH capture / MED release-dayWayback-verified 2014-04-11; the changelog claims a 2014-03-31 initial release.

  • 2014-07-15

    Google announces Project Zero, 8 days before the root commit; its 90-day disclosure deadline (+14-day grace) is formalized 2015-02-13. The July-2014 disclosure-norms fortnight; conceptual antecedent (dashed). HIGH

  • 2014-07-23

    bugcrowd/disclosure-policy first commit (10ea3e1, Chris Raethke). Files: responsible_disclosure_policy.md, setting_up_a_responsible_disclosure_program.md. HIGHGoal: an open-source, copy-pasteable disclosure framework with built-in legal safe harbor for researchers.

  • 2014-07-24

    Launch press (approximately seven hours after the recorded commit time): PRNewswire “Bugcrowd Releases Open Source Responsible Disclosure Framework” + Threatpost, both pointing at the repo and quoting CipherLaw’s Jim Denaro (“…researchers… are not discouraged from reporting… because of the legal risks”). The git + Wayback + press triangle, closed. HIGH

  • 2014-10-16

    Earliest Wayback capture of the Bugcrowd framework repo (HTTP 200). HIGH

Timeline

2017–2018, the legal-safe-harbor idea crystallizes

  • 2017

    Amit Elazari presents this work at BSidesLV and DEF CON Skytalks, as documented in her Enigma speaker biography. These appearances do not establish when the research began. MEDGoal: make legal safe harbor a standardized norm, not a per-program favor.

  • 2017-07

    U.S. DOJ Criminal Division publishes “A Framework for a Vulnerability Disclosure Program for Online Systems,” v1.0, prosecutorial guidance for designing VDPs that reduce researcher legal risk. Elazari’s template README credits it. HIGH

  • 2017-08

    CERT/CC publishes The CERT Guide to Coordinated Vulnerability Disclosure (CMU/SEI-2017-SR-022), the canonical CVD handbook. HIGH

  • 2018-01-18

    Enigma 2018 talk “Hacking the Law: Are Bug Bounties a True Safe Harbor?” HIGH

  • 2018-03-21

    Dropbox, “Protecting Security Researchers”: the first “‘authorized’ conduct under the CFAA” + DMCA-waiver safe-harbor language in this corpus. HIGH

  • 2018-03-29

    EdOverflow/legal-bug-bounty templates repo created (README credits Dropbox). HIGH

  • 2018-04-12

    SSRN paper “Private Ordering Shaping Cybersecurity Policy: The Case of Bug Bounties” (SSRN ID 3161758). HIGH

Timeline

2015–2018, the disclose.io domain's first life (a guidance site + a contact "List")

Before the Aug-2018 safe-harbor relaunch, the disclose.io domain already served a different project. This is brand/domain pre-history, not a dioterms text ancestor, kept together here (slightly out of strict date order) so the domain's own story stays in one place.

  • 2015-12-11

    Earliest Wayback capture of the disclose.io domain (HTTP 200), a GitHub-Pages site titled “Disclose.io, community-maintained vulnerability disclosure guidance”: researcher legal-risk guidance (CFAA, DMCA, EFF / Rapid7 links) plus a searchable “List” interface backed by an Algolia security_list index for looking up a domain's security-contact aliases. HIGH (capture)Guidance content existed at the domain by 2015-12-11 (captured at /index.html; the relaunched homepage returns 200 only from 2018), ~2.5 years before the terms project, and it is a directory antecedent of diodb / directory.disclose.io on the contact-lookup axis. This is about the domain, not the modern site.

  • 2018-01-18

    The first-life guidance site is still served, the last archived state before the pivot (previously cited on this page as the domain's “first live content”; the 2015 capture supersedes it). Continuity of ownership/authorship between this 2015–18 incarnation and the Aug-2018 relaunch is unverified, the snapshot shows only that the domain served this content, not who ran it.

Timeline

2018, disclose.io is born

  • 2018-05-16

    disclose/diodb first commit (0158e3b). HIGH

  • 2018-08-02

    disclose.io launches (Bugcrowd + Amit Elazari), explicitly merging the three predecessors. HIGHGoal (2018 launch-day, verbatim): “a collaborative and vendor-agnostic project to standardize best practices around safe harbour for good-faith security research.”

  • 2018-08-02

    The launch-day Wayback capture already shows the full terms project: “Read the core terms,” all three tributaries named, and “so our hacker friends don’t go to jail.” (Corrects an earlier “first terms capture = 2018-08-29”.) HIGH

  • 2018-10

    ISO/IEC 29147 second edition published (the 2014 first edition withdrawn/superseded), two months after disclose.io’s launch; the standards track and the safe-harbor track converge on the same year. HIGH

  • 2018-12-07

    diodb’s first real program list: 426 organizations (698675f). HIGHA directory records programs and policy attributes; listing alone does not establish safe-harbor adoption.

Timeline

2020, a canonical home and automated discovery

  • 2020-06-30

    disclose/dioterms repo first commit (851a906). HIGH

  • 2020-07-15

    First canonical terms text in the disclose org (be213be, generic-core-terms.md) with an explicit “Safe Harbor” section. HIGH

  • 2020-08-12

    disclose/diosts (Go security.txt scraper) created to discover disclosure contacts and policies. HIGH

  • 2020-09-02

    CISA issues BOD 20-01, requiring U.S. federal civilian executive branch agencies to publish vulnerability disclosure policies for internet-accessible systems and services and maintain supporting processes. Source. HIGH

  • 2020-11-15

    Wayback captures the actual dioterms text + the 2020 mission, verbatim: “To drive vulnerability disclosure adoption through safety, simplicity, and standardization.” HIGH

  • 2020-11-16

    Directory expansion: the diosts bot auto-imports security.txt-discovered programs, jumping diodb 981 → 3,524 entries in one commit (aee74f1). This records an automated import, not 2,543 new adoptions. A causal connection to CISA’s directive has not been established. HIGH

Timeline

2021–2022, the vision broadens

  • 2021-03-29

    Casey Ellis states the project’s intent on the record in his #HackerCon talk (@hacknotcrime × @redteamvillage), video published 2021-03-29: vision — “a healthy and ubiquitous internet immune system”; mission — “standardize and promote neighborhood watch for the internet”; and an end-game where the trust seal succeeds by becoming unnecessary (“so standard and so normalized that we don’t really need it anymore”). A founder intent statement, not a terms artifact. Video, 09:24. Quotations are retained from the prior caption review; the speaker’s event record dates the talk to 27 March, distinct from the upload date. HIGHNames the flywheel the project was built to spin: an org adopts the terms → the directory records it → it earns the seal → the next org sees it and follows.

  • 2021-04-11

    dioterms licensed CC0-1.0 (public domain): LICENSE added in 365c5f8, the terms become genuinely reusable public infrastructure. HIGHGoal: remove every reuse barrier.

  • 2022-04-27

    RFC 9116 publishes security.txt, an Informational RFC for machine-readable reporting contacts and policy links. It complements human-readable policies; the file itself does not grant permission to test. Source. HIGH

  • 2022-07-14

    Wayback captures the 2022 mission, verbatim: “a cross-industry, vendor-agnostic standardization project for safe harbor best practices… a straightforward maturity model.” HIGH

Timeline

2021–2023, legal and policy context

These are parallel developments. Private authorization, prosecutorial policy and statutory duties have different effects. These sources do not establish dioterms’ influence on the laws or decisions.

  • 2021-06-03

    Van Buren v. United States narrows the CFAA’s “exceeds authorized access” provision. The decision does not create blanket researcher immunity; footnote 8 leaves open whether relevant access limits must be technological or may also arise from policies and contracts. Source. HIGH

  • 2022-05-19

    DOJ revises its CFAA charging policy to direct federal prosecutors to decline prosecution for qualifying good-faith security research. It is a prosecutorial policy, not a statutory exemption or a waiver of private claims. Source. HIGH

  • 2022-11-16

    HackerOne “Gold Standard Safe Harbor”, “a short, broad, easily-understood safe harbor statement that’s simple for customers to adopt” (early adopters: GitLab, KAYAK, Yahoo). Parallel industry standardization; the announcement does not establish derivation from dioterms. HIGH

  • 2022-12-27

    NIS2 is published. Article 7(2)(c) requires national policies promoting and facilitating CVD; Article 12 provides for coordinating CSIRTs and a European vulnerability database. The transposition deadline was 17 October 2024. Source. HIGH

  • 2023-02-15

    Belgium introduces a vulnerability-research framework with conditional protection: necessary and proportionate testing, no malicious or fraudulent intent, notification to the affected organization and CCB, and CCB permission before public disclosure. Source. HIGH

Timeline

2024–2026: from legislation to infrastructure

European CVD infrastructure and product obligations, with their distinct effective dates.

  • 2024-12-10

    The Cyber Resilience Act enters into force. Its manufacturer requirements include a CVD policy under Annex I, Part II(5), but general application is 11 December 2027. Entry into force does not make all duties immediately applicable. Source. HIGH

  • 2025-05-13

    ENISA announces the European Vulnerability Database is operational, implementing NIS2’s database requirement and providing vulnerability, mitigation and exploitation information. Source. HIGH

  • 2026-09-11

    CRA Article 14 reporting obligations begin for actively exploited vulnerabilities and severe incidents affecting covered products. ENISA’s Single Reporting Platform becomes operational; it is distinct from the public EU vulnerability database. Source. HIGH

Still ahead, as of this review: the CRA’s general product and vulnerability-handling requirements apply from 2027-12-11. These CVD duties do not establish universal permission for security testing.

Timeline

Public-sector disclosure and directory coverage

  • 2016-11-21

    U.S. DoD VDP goes always-on (“Hack the Pentagon” was the earlier spring-2016 pilot). HIGHA public-sector VDP milestone preceding the 2018 terms project; this does not establish adoption of dioterms.

  • 2023→2025

    Target 2023-11-03 (f71528c) · Dell 2024-03-10 (ddf2f8e) · a16z 2024-09-28 (6f5b57d) · SIX Group 2025-07-20 (0e8e445), each dated by the diodb commit that added it. These are listing dates, not program launch or safe-harbor adoption dates. HIGH

  • 2026

    The rebuilt disclose.io site restates the mission as “make vulnerability disclosure safe, simple, and standardized for everyone”, the 2020 triad, now addressed to “everyone” with five persona on-ramps. HIGH

  • by 2026-06-03

    directory.disclose.io, the hosted diodb front-end (“Search vulnerability disclosure and bug bounty programs”), first Wayback-captured. The capture is an upper bound, not a launch date. MED

Goal evolutionDated mission statements and an explicitly labelled summary.

WhenStated goal / missionSource
2014Summary, not a quotation: an open-source disclosure policy with researcher-protection commitmentsbugcrowd/disclosure-policy
2015–2018
(pre-pivot)
“Disclose.io is a community-maintained resource for vulnerability disclosure”, the first-life guidance site + contact “List”, live from 2015-12-11 through Jan 2018, before the terms-project pivot of Aug 2018Wayback 2015-12 / 2018-01
2018
(launch)
“a collaborative and vendor-agnostic project to standardize best practices around safe harbour for good-faith security research”Wayback 2018-08-02
2020“To drive vulnerability disclosure adoption through safety, simplicity, and standardization”Wayback 2020-11-15
2021
(talk)
As articulated by the founder in the 2021 talk (not a site-published mission): vision “a healthy and ubiquitous internet immune system”; mission “standardize and promote neighborhood watch for the internet” — the only first-person, spoken-word source in this tableEllis, #HackerCon 2021
2022“a cross-industry, vendor-agnostic standardization project for safe harbor best practices… a maturity model”Wayback 2022-07-14
2026“make vulnerability disclosure safe, simple, and standardized for everyone”Wayback 2026-06-04

The arc: a legal artifact (2014 safe-harbor template) → a terms standardization project (2018) → a standardization project with a maturity model (2020–22).

Where the language came fromSelected historical policies and contemporary dioterms, compared with explicit evidence limits.

The safe-harbor clause, assembled across three organizations

The selected texts illustrate how researcher-protection commitments became more explicit. Their sequence does not establish the first use of safe harbor anywhere:

2014 · Bugcrowd, the goodwill promise, no statutes HIGH

“If you follow these guidelines… we commit to: Not pursue or support any legal action related to your research.”

2018 · Dropbox, explicit authorization in this selected corpus (Mar 21, 2018), eight days before Elazari’s template repo, which credits it HIGH

“…we consider actions consistent with the policy as constituting ‘authorized’ conduct under the Computer Fraud and Abuse Act (CFAA)” · “a pledge that we won’t bring a Digital Millennium Copyright Act (DMCA) action…” · “…if a third party initiates legal action, Dropbox will make it clear when a researcher was acting in compliance with the policy (and therefore authorized by us).”

2018 · Elazari #legalbugbounty, standardizes it into a reusable, statute-naming template HIGH

“…‘authorized’ conduct under the Computer Fraud and Abuse Act, the DMCA and applicable anti-hacking laws such as Cal. Penal Code 502(c).”

Its README credits the basis: “…the DOJ guidelines… and some leading policies like Dropbox.”

dioterms · contemporary text, the parameterized synthesis HIGH

“Authorized concerning any applicable anti-hacking laws, and we will not initiate or support legal action… Authorized concerning any relevant anti-circumvention laws… Exempt from restrictions in our Terms of Service (TOS) and/or Acceptable Usage Policy (AUP)… Lawful, helpful… and conducted in good faith.”

Similarity is not provenance. This is concordance + chronology across the texts actually fetched, not a commit-level “who-typed-what” diff. The order is corroborated by disclose.io’s own “three tributaries” attribution (Bugcrowd framework + Elazari + Dropbox) and Elazari’s explicit Dropbox credit, but generic legalese and parallel drafting are not excluded.

Where the language came from

Feature comparisonHistorical documents and contemporary dioterms. This comparison does not establish universal firsts; inaccessible ISO provisions are not assessed.

FeatureRFPolicy ’00IETF ’02ISO ’14Bugcrowd ’14Dropbox ’18Elazari ’18dioterms today
Response / disclosure timing✓5 working days to respond✓30 days?✓90 days◐–✓parameterized
Researcher conduct✓✓?✓✓–✓
Vendor commitments◐✓?✓✓–✓
Legal safe harbor✕no authorization clause✕?◐goodwill✓✓CFAA · DMCA✓✓+ Cal. 502✓structured
Bilateral structure✕◐?✓✓✓✓
Self-labelFull DisclosureResponsibleVuln disclosureResponsible Disc.VDPSafe HarborVDP / BBP
✓present ✓✓strongly present ◐partial –clause-insert (not a whole policy) ✕absent ?not retrievable (paywalled)

The terminology arc

Policy discovery: security.txt can link to any disclosure policy. It does not make dioterms machine-readable or grant research authorization. See RFC 9116 §5.5.

Full Disclosure (2000, completeness) → Responsible (2002, process) → Coordinated / CVD (2010–14, neutrality, CERT/CC: “responsible… is a matter of opinion… framed within the values of whoever is using the term”) → Safe Harbor (2017–18, legality). dioterms speaks all four dialects at once.

How the needs evolved

  • 2000, vendor stonewalling → communication expectations (RFPolicy v2’s five working days to respond, with continuing dialogue; not a five-day fix deadline).
  • 2002, multi-party chaos → roles + process (the Reporter / Vendor / Coordinator triad).
  • 2010–14, “responsible” weaponized → neutral terminology (CVD) + a vendor-side standard (ISO 29147).
  • 2014, every program reinvents the policy → a reusable, bilateral template (Bugcrowd).
  • 2017–18, researchers face legal uncertainty under the CFAA and DMCA → a legally-operative safe harbor (Dropbox ships it; Elazari standardizes it).
  • 2020–22, adoption at scale, machine discovery, government mandate → reusable terms, machine-readable contact discovery and scoped government requirements (dioterms, security.txt, CISA BOD 20-01).

Disclosure practice developed along several overlapping tracks: public discussion, vendor coordination, reporting contacts, reusable policy language and researcher protection. They are related needs, not a single inevitable sequence.

Confidence legend & honest caveats

HIGH = a directly inspectable source supports the specifically stated fact; this does not validate every inference from it.   MED = single/secondary source or non-day-precise date.

Caveats (carried forward, not hidden):

  • The often-cited “DEF CON 26 Legal Bug Bounty talk” could not be confirmed as a titled DEF CON 26 main-stage talk, likely a conflation with 2017 Skytalks (unrecorded).
  • The paper is cited by SSRN ID 3161758. Its page bot-blocks curl (403) but renders live in a browser.
  • ISO 29147’s first-edition day isn’t shown on iso.org; the 2014 edition year is confirmed.
  • ~2-year gap between “terms provably existed on disclose.io” (2018-08) and “terms text is archived word-for-word” (2020-11), Wayback never grabbed the original core_terms file, only the repo’s tree listing.
  • An earlier Bugcrowd terms artifact exists, but it isn’t the root. Bugcrowd’s “Standard Disclosure Terms” (2014-03) carries researcher-protection intent but no safe-harbor legal clause, and no documented derivation into dioterms. The falsifiable claim is specifically about the earliest safe-harbor template; that still resolves to 2014-07-23.
  • Earliest-found is not earliest-that-exists. Git archaeology establishes the earliest commit located in this search, not proof that no earlier artifact could ever surface. The 2014-07-23 headline is a falsifiable conjecture, retestable as GitHub/Wayback indexes grow.
References & archives

References & archivesTargeted research refresh: 2026-09-21. Earlier source checks are dated July 2026; retained sources have not all been rechecked. New and corrected entries link directly to their evidence. Archive availability can change.

GitHub, commits & repos (ground truth)

References & archives

Web archives, Wayback Machine snapshots

References & archives

Papers, standards, RFCs & directives

References & archives

Predecessor policy texts (fetched verbatim for the lineage)

References & archives

Primary social & press

References & archives

Scholarly & legal literature referencing disclose.io (reception)

Peer-reviewed and scholarly works that name or cite disclose.io in their text, from a one-line reference to substantive discussion, evidence of the project's reception in academic and legal literature (distinct from the provenance lineage above). Surfaced via an OpenAlex full-text query plus a targeted PDF sweep; the literal “disclose.io” reference was read and confirmed in each source's open-access full text (retrieved 2026-07-06), and most bug-bounty / CVD papers checked did not mention it, so these are genuine hits. Primary DOI / publisher links given; preprint links should be checked for subsequent revisions.

  • DOCPfefferkorn, R. (2022), “Shooting the Messenger: Remediation of Disclosed Vulnerabilities as CFAA ‘Loss’,” Richmond Journal of Law & Technology 29(1), cites the disclose.io-hosted Voatz response letterjolt.richmond.edu/files/2022/11/Pfefferkorn-Manuscript-Final.pdf
  • DOCZrahia, A. (2024), “Navigating vulnerability markets and bug bounty programs: A public policy perspective,” Internet Policy Review 13(1), recommends supporting “projects such as Disclose.io”doi.org/10.14763/2024.1.1740
  • DOCIngalls Information Security (2022), “disclose.io — Managing Disclosure of Vulnerabilities and Risk,” company white paper hosted by the National Association of Secretaries of State (Summer 2022), recommends building a VDP “using an online resource like disclose.io” and cites policymaker.disclose.io (a company publication, not an association endorsement; literal “disclose.io” ×5)nass.org/…/white-paper-ingalls-nass-summer22.pdf
  • DOCPark, S. & Albert, K. (2024), A Researcher’s Guide to Some Legal Risks of Security Research (v2.0), Harvard Cyberlaw Clinic + EFF, “The Disclose.io Safe Harbor project maintains a useful list…”clinic.cyber.harvard.edu/…/Security-Researchers-Guide-8-2-24.pdf
  • DOCAlbert, K., Penney, J. & Siva Kumar, R.S. (2024), “Ignore Safety Directions. Violate the CFAA?,” GenLaw @ ICML 2024, cites threats.disclose.ioblog.genlaw.org/pdfs/genlaw_icml2024/39.pdf
  • DOCKenway, J. & François, C. (2021), Bug Bounties For Algorithmic Harms?, Algorithmic Justice League, lists Disclose.io among community-led disclosure initiativesajl.org, Bug Bounties For Algorithmic Harms (PDF)
  • DOCNeef, S., Schlunke, C. & Hennig, A. (2026), “Do (Not) Tell Me About My Insecurities: … Coordinated Vulnerability Disclosure in Germany …,” arXiv 2606.25950 (retrieved 2026-07-06), compares its dataset against disclose.io/programs/arxiv.org/abs/2606.25950
  • DOCHall, P., Mundahl, O. & Park, S. (2025), “The Pitfalls of ‘Security by Obscurity’ and What They Mean for Transparency,” AAAI 39(27), footnote lists disclose.io among report-intake channels (reference read in the arXiv preprint 2501.18669, retrieved 2026-07-06)doi.org/10.1609/aaai.v39i27.35022
  • SRCReference / knowledge bases: Wikidata models both disclose.io (Q140450099) and the dioterms (Q140446836) as first-class entities; Crunchbase carries a disclose.io org profile; the Wikipedia “Bugcrowd” article references disclose.io (no standalone article yet)wikidata Q140450099 · Q140446836 · crunchbase
Provenance. Research updated 2026-09-21. Git metadata dates the recorded artifact; contemporaneous announcements and archives independently support public availability. A snapshot proves content was served by its capture time, not when it launched or who operated it. Earliest located is not earliest possible. Legal developments are context, not evidence of dioterms’ influence. Read the refresh notes and source record.

Source project: history.disclose.io · full sources ledger retained alongside the timeline. Research updated 2026-09-21. Source repository.

← → / space to move · F fullscreen · ⌘P to PDF
01 / 24