Draft
Upload the PoC, write-up, affected versions, CVSS vector, CWE tags, screenshots, references, and mitigation notes.
Prepare private disclosures, preserve vendor timelines, set embargoes, manage waiting periods, publish useful advisories, and surface reputation signals without giving vendors control over the workflow.
Release workflow
Demo data updates locally.
Earliest pending disclosure window.
Cancel, delay, modify, or delete.
Searchable unless removed by policy.
Public demo
Filter live demo disclosures by status, severity, vendor, product, CWE, or reputation signal.
Lifecycle
This demo makes the core workflow visible: draft privately, set an embargo, enter a waiting period, retain researcher control, then publish automatically unless the researcher cancels or delays.
Upload the PoC, write-up, affected versions, CVSS vector, CWE tags, screenshots, references, and mitigation notes.
Keep details private while the researcher coordinates externally with the affected vendor or maintainers.
After embargo expiration, the researcher still has a final window to cancel, delay, modify, or delete before release.
The advisory becomes searchable, machine-readable, attributable, shareable, and available through public feeds.
Reputation
Reputation should be generated from public disclosure records, researcher-entered timelines, community feedback, evidence attachments, and moderation safeguards.
Verified reports, documentation quality, trusted reviews, contribution history, reproducibility, and public advisory quality.
Acknowledgement time, remediation time, ignored disclosures, disputes, payment issues, safe harbor quality, and researcher treatment.
Researcher-submitted feedback on report handling, duplicate handling, scope issues, payment reliability, and retaliation or bans.
Moderation, evidence attachment, rate limits, anti-brigading controls, reputation weighting, reporting, and appeal workflows.
Useful by default
Every public page should serve researchers, defenders, nonprofits, journalists, incident responders, and the broader security community.
PoC details, Markdown write-up, affected products, versions, platform tags, references, and advisory IDs.
CVSS score, CVSS vector, severity rating, CWE tags, CPE/product tags, known exploitation, and patch availability.
Researcher-entered vendor outreach, acknowledgement, response quality, dispute status, remediation status, and payment issues.
RSS, JSON, API access, webhooks, search indexing, and machine-readable vulnerability metadata without a paywall.
Before launch
A researcher-first disclosure platform needs clear rules for high-risk research, disputed claims, legal threats, malware handling, moderation, appeals, and researcher safety before public launch.
Open-source nonprofit build
This page is a functional demo shell: disclosure list, statuses, timeframes, filtering, selected advisory preview, reputation signals, waiting-period logic, and core product model.