Sign in

Safe Harbor Policy Template

Legal uncertainty kills vulnerability disclosure programs before they start. Researchers will not report vulnerabilities if they fear legal retaliation. Organizations cannot benefit from security research without providing clear legal protection for good-faith testing.

This template provides legally defensible language for authorizing security research within defined scope. It establishes explicit safe harbor protection under computer fraud and abuse laws while defining reasonable boundaries for testing activities.

Authorization and Safe Harbor

We consider security research conducted consistent with this policy to constitute authorized conduct under applicable computer fraud and abuse laws. We will not pursue civil action or initiate complaints to law enforcement for accidental, good-faith violations of this policy.

This authorization is contingent upon compliance with the testing boundaries and researcher obligations defined in this policy. Researchers who exceed these boundaries or fail to meet these obligations may forfeit safe harbor protection.

Activities that comply with this policy are explicitly authorized regardless of whether they might otherwise violate terms of service, acceptable use policies, or other contractual restrictions.

The authorization language must be explicit and legally precise. Generic statements about "authorized testing" are insufficient—the policy must clearly state that research conducted under the policy constitutes authorized access under relevant laws.

Testing Boundaries

Security research under this policy must remain within the following technical and legal boundaries:

Data Access: Do not access, modify, or exfiltrate data beyond what is necessary to demonstrate a vulnerability. Access to personal data, financial information, or confidential business data is prohibited regardless of technical feasibility.

Service Availability: Avoid testing methods that could disrupt service availability or performance for other users. This includes denial-of-service attacks, resource exhaustion testing, and load testing beyond normal usage patterns.

Account Integrity: Do not attempt to access accounts that do not belong to you. Account enumeration, credential brute-forcing, and social engineering are prohibited.

Physical Security: This policy covers only technical vulnerabilities in digital systems. Physical security testing, social engineering of employees, and access to physical premises are outside the scope of this authorization.

Testing must be conducted using your own accounts and test data. Creating accounts for testing purposes is permitted provided account information is accurate and testing activities are clearly identified.

Testing boundaries must be technically specific rather than legally defensive. Researchers need clear guidance about what constitutes acceptable testing methods and what activities exceed the scope of authorization.

Researcher Obligations

Researchers operating under this safe harbor policy must meet the following obligations:

Prompt Reporting: Report vulnerabilities promptly after discovery through the designated contact methods. Delayed reporting may increase risk to users and reduce the effectiveness of coordinated disclosure.

Detailed Documentation: Provide sufficient technical detail to enable vulnerability reproduction and impact assessment. Include steps to reproduce, affected systems or components, and potential impact scenarios.

Coordinated Disclosure: Allow reasonable time for vulnerability remediation before public disclosure. Standard disclosure timeline is 90 days from initial report, with extensions available for complex issues requiring architectural changes.

Good Faith Communication: Engage constructively with our security team throughout the disclosure process. Provide additional information when requested and participate in remediation discussions when appropriate.

Failure to meet these obligations may result in loss of safe harbor protection and potential legal action under applicable laws.

Researcher obligations must be reasonable and technically achievable. Unrealistic reporting requirements or overly restrictive disclosure timelines will discourage participation and reduce program effectiveness.

Coordinated Disclosure Process

We commit to the following coordinated disclosure process for vulnerabilities reported under this policy:

Initial Response: We will acknowledge receipt of vulnerability reports within 72 hours and provide a tracking reference for follow-up communication.

Triage and Validation: We will complete initial triage and validation within one week of report receipt. This includes reproducing the vulnerability, assessing impact, and determining remediation priority.

Regular Updates: We will provide status updates at least every two weeks until vulnerability resolution. Updates will include remediation progress, expected timelines, and any complications affecting the disclosure schedule.

Disclosure Coordination: We will coordinate public disclosure timing with researchers, providing at least 48 hours notice before publishing security advisories or other public communications about the vulnerability.

We may request disclosure timeline extensions for complex vulnerabilities requiring architectural changes or coordination with third-party vendors. Extension requests will include detailed justification and revised timelines.

Organizations must commit to specific response timelines and communication practices. Researchers invest significant time in vulnerability research—the disclosure process should reflect that investment with professional and responsive communication.

Legal Protections

This policy provides explicit legal protection for security research conducted within its scope:

No Legal Action: We will not pursue civil litigation or criminal prosecution against researchers who comply with this policy, even if their activities might otherwise violate terms of service or other agreements.

No Law Enforcement Referral: We will not refer researchers to law enforcement agencies for activities conducted in compliance with this policy.

Active Defense: We will actively support researchers against legal action by third parties related to security research conducted under this policy, including providing documentation of authorization and policy compliance.

Researchers with questions about policy scope or legal protections should contact our legal team at legal@[organization].com before conducting testing activities.

Legal protections must be explicit and enforceable. Generic statements about cooperation are insufficient—the policy must commit to specific actions that protect researchers from legal risk.

Implementation Notes

This template requires customization for specific organizational contexts. Legal teams should review the language for consistency with local laws and regulations. Technical teams should review testing boundaries for alignment with operational constraints and risk tolerance.

The policy should be published at a stable URL referenced in security.txt files and linked from security contact pages. Changes to the policy should be versioned and communicated to active researchers.

Organizations operating in multiple jurisdictions may need jurisdiction-specific policy variants. Legal consultation is recommended for organizations subject to specific regulatory requirements or operating in jurisdictions with unclear computer fraud and abuse law interpretations.