
Payatu Disclosure Policy
Our disclosure policy, start to finish.
When Payatu finds a vulnerability, we notify the vendor first and give them time to fix it before anything becomes public. This policy sets out each stage, the 90-day disclosure window, and how the process stays confidential until then.
Day 0 · We notify the vendor
We disclose the vulnerability to the vendor and wait for acknowledgement.
By day 7 · We try again
We disclose the vulnerability to the vendor and wait for acknowledgement.
By day 10 · The path splits
If the vendor has acknowledged us, we convey that the 90-day public-disclosure window has begun, and provide technical details if the vendor asks. If there is still no acknowledgement, we proceed toward public disclosure and inform CERT or another disclosure coordinator, chosen case by case.
Before day 90 · The vendor patches
The vendor fixes and tests the vulnerability, announces the patch, and informs Payatu.
After the patch, or day 90 · We disclose
We make our public disclosure after 90 days from notification or after the vendor releases a patch, whichever happens first.
WHAT WE PUBLISH
Where the findings go after disclosure
Once a vulnerability is disclosed, we share our findings, with technical details, for the benefit of
the larger community through:
the larger community through:
- Blogs
- Technical papers at security conferences, anywhere in the world
- Inclusion in our training courses and study material
CONFIDENTIALITY AND SECURE COMMUNICATION
How we handle the non-disclosure period
For communication with the vendor during disclosure, the policy sets the following:
- Throughout the non-disclosure period, we expect regular communication with the vendor, and we keep it confidential.
- Only the finder of the vulnerability and the Payatu-appointed authority for the Disclosure Response Program are in the communication loop.
- Communication with the vendor and progress through each stage are documented and tracked on Payatu's internal systems.
- We prefer cryptographically secure communication channels with vendors, where they support and provide them.
As a matter of policy, we keep CERT or other industry-trusted disclosure coordinators informedof our findings. This is the finder's right and does not require the affected vendor's permission.












