Sign in

Safe Harbor Policy Creation Guide

A guide to creating legal protection for security researchers through safe harbor policies in your vulnerability disclosure program.

What is a Safe Harbor Policy?

A safe harbor policy provides legal protection to security researchers who discover and report vulnerabilities in good faith. It establishes clear boundaries for authorized security testing and shields researchers from legal action when they follow responsible disclosure practices.

Key Purpose: Safe harbor policies protect both organizations and researchers by clearly defining acceptable security research activities and the legal protections offered to compliant researchers.

Essential Components

1Scope Definition

Clearly define what systems, applications, and services are covered by your safe harbor policy:

In-Scope Assets

  • Primary domain (example.com) and subdomains
  • Mobile applications (iOS, Android)
  • API endpoints and web services
  • Public-facing infrastructure

Out-of-Scope Assets

  • Third-party services and vendor systems
  • Physical security testing
  • Social engineering attacks
  • Internal networks and systems

2Authorized Testing Activities

Define what security testing activities are explicitly authorized:

Authorized Activities:
• Automated vulnerability scanning with reasonable rate limits
• Manual security testing of web applications
• Analysis of client-side code and mobile applications
• Testing authentication and authorization mechanisms
• Cross-site scripting (XSS) and injection testing
• Testing for insecure direct object references

Rate Limits:
• Maximum 10 requests per second per endpoint
• No more than 1000 total requests per hour
• Avoid testing during peak business hours (9 AM - 5 PM local time)

3Prohibited Activities

Clearly state what activities are not permitted, even under safe harbor:

  • Accessing, modifying, or deleting user data
  • Disrupting or degrading system performance
  • Performing denial-of-service attacks
  • Social engineering of employees or users
  • Physical attacks against facilities
  • Violating privacy or accessing personal information

4Legal Protection Language

Include explicit legal protection statements:

Legal Safe Harbor:
[Organization] will not pursue legal action against security researchers who:

1. Act in good faith to identify and report security vulnerabilities
2. Follow the guidelines outlined in this policy
3. Report findings through our designated disclosure channel
4. Provide reasonable time for remediation before public disclosure
5. Do not access, modify, or delete user data
6. Do not disrupt our services or systems

This includes protections under:
• Computer Fraud and Abuse Act (CFAA)
• Digital Millennium Copyright Act (DMCA)
• State and local computer crime laws
• Terms of service and other contractual restrictions

5Reporting Requirements

Specify how researchers should report vulnerabilities:

Required Information

  • Detailed description of the vulnerability
  • Steps to reproduce the issue
  • Potential impact and risk assessment
  • Proof-of-concept (if applicable)
  • Affected systems or components

Contact Information

  • Dedicated security email: [email protected]
  • Encrypted communication via PGP key
  • Web-based reporting portal (preferred)
  • Expected response timeframe: 48 hours

Sample Safe Harbor Policy Template

# Safe Harbor Policy

## Overview
[Organization Name] values the security community and recognizes the important role that security researchers play in keeping our users safe. This policy describes our commitment to protecting security researchers who report vulnerabilities to us in good faith.

## Scope
This policy applies to security research conducted on the following assets:
• [Primary domain] and its subdomains
• [Mobile applications]
• [API endpoints]
• [Other in-scope assets]

## Authorization
We authorize security research on in-scope assets provided that you:
• Follow responsible disclosure practices
• Respect user privacy and data
• Avoid disrupting our services
• Report findings through our official channels

## Safe Harbor
We commit to:
• Not pursue legal action against researchers who comply with this policy
• Work with researchers to remediate valid vulnerabilities
• Recognize researchers publicly (with permission)
• Provide timely updates on remediation progress

## Prohibited Activities
Do not:
• Access, modify, or delete user data
• Disrupt or degrade service performance
• Conduct physical attacks or social engineering
• Violate applicable laws or regulations

## Reporting
Report vulnerabilities to: security@[domain]
Include: Detailed description, reproduction steps, and impact assessment
Expected response: Within 48 hours of receipt

## Legal
This policy supersedes any conflicting terms of service. Compliance with this policy is a defense to any claim under the Computer Fraud and Abuse Act or similar state laws.

Legal Considerations

1Jurisdiction and Applicable Law

Consider the legal framework in your jurisdiction:

  • United States: Address CFAA, state computer crime laws, and DMCA
  • European Union: Consider Computer Misuse laws and GDPR implications
  • International: Be aware of cross-border legal complexities

2Terms of Service Integration

Ensure your safe harbor policy integrates properly with existing legal agreements:

Important: Your safe harbor policy should explicitly state that it supersedes conflicting terms of service or other agreements for authorized security research activities.

3Insurance and Liability

Consider the impact on your organization's insurance and liability:

  • Review cyber insurance policies for coverage of authorized testing
  • Understand potential liability for researcher actions
  • Consider indemnification clauses for researchers

Implementation Best Practices

1Legal Review

  • Have your legal team review the policy before publication
  • Ensure compliance with local and international laws
  • Consider consulting with cybersecurity law specialists

2Publication and Accessibility

  • Publish the policy on your main website
  • Include links in your security.txt file
  • Make it easily discoverable through search
  • Provide the policy in multiple languages if applicable

3Regular Updates

  • Review and update the policy annually
  • Update when systems or legal requirements change
  • Communicate changes to the security community
  • Maintain version history and change logs

Common Mistakes to Avoid

Policy Pitfalls

  • Vague scope definition: Be specific about what systems are covered
  • Overly restrictive terms: Don't make compliance impossible
  • Conflicting legal terms: Ensure consistency across all policies
  • Unrealistic expectations: Set achievable reporting and response requirements
  • Missing legal protections: Explicitly address applicable laws

Measuring Policy Effectiveness

Key Metrics

  • Research participation: Number of researchers engaging with your program
  • Report quality: Percentage of valid, actionable vulnerability reports
  • Legal incidents: Number of legal disputes or misunderstandings
  • Community feedback: Researcher satisfaction and policy clarity ratings

Continuous Improvement

  • Gather feedback from security researchers
  • Monitor industry best practices and standards
  • Track legal developments affecting safe harbor policies
  • Regular policy effectiveness reviews

Ready to Implement?

A well-crafted safe harbor policy is essential for any vulnerability disclosure program. It protects both your organization and security researchers while fostering a collaborative security ecosystem.

Related Resources

Security.txt Implementation

Learn how to implement RFC 9116 security.txt files to make your security policy discoverable.

Read Guide →

Vulnerability Triage Training

Master the process of triaging and managing vulnerability reports in your program.

Start Training →