disclose.io · a sourced history of the terms
Where the disclose.io safe-harbor terms actually came from, traced to the earliest internet-verifiable ancestor, with every claim anchored to a live archive.
first commit of bugcrowd/disclosure-policy, hash 10ea3e1, “first commit,” authored by Chris Raethke (Bugcrowd’s founding CTO) at 23:02:41 −0700.
That repo’s own GitHub description draws the inheritance explicitly:
“Open Source Vulnerability Disclosure Framework. Maintained by Bugcrowd and Cipherlaw. Merged with github.com/disclose/dioterms.”
The defining feature of dioterms, bilateral safe harbor, is already present in that very first 2014 file (responsible_disclosure_policy.md):
“If you follow these guidelines… we commit to: Not pursue or support any legal action related to your research…”
The dioterms language is therefore ~4 years older than the disclose.io brand it later fed into. Note this proves a Bugcrowd disclosure-policy repo existed in 2014, it does not prove disclose.io was co-founded in 2014 (a separate, bio-sourced claim). Keep those two facts apart.
2014-07-23 23:02:41 −0700), no rebase/backdate divergence.rev-list --parents shows no parent → a genuine initial commit, not a migrated history.This is a falsifiable claim: it stands until an earlier Bugcrowd template, gist, or snapshot surfaces. The 2026-05-31 refutation hunt found nothing earlier in Bugcrowd’s repos.
Solid lines mark documented inheritance, a repo states it merged something, so that something is a direct ancestor. Dashed lines mark conceptual antecedents: the same problem space, with no sourced derivation.
The solid chain is sourced: disclose.io’s own 2018 launch page names the three tributaries it merged (Bugcrowd+CipherLaw’s 2014 framework, Elazari’s #legalbugbounty, Dropbox’s researcher-protection language), and bugcrowd/disclosure-policy’s description states it merged into disclose/dioterms. The 2000–2014 norms (RFPolicy, IETF draft, ISO 29147) are dashed: they shaped the problem space of standardized disclosure, but no document shows Bugcrowd’s framework deriving its text from them, antecedents, not parents.
Platform pre-history, the crowdsourced-security market (the demand soil)
Bugcrowd & HackerOne both founded; Bugcrowd launched first. Per HackerOne co-founder/CTO Alex Rice, on record: “Both founded 2012, @Bugcrowd launched first! @Hacker0x01 kickoff 2/2012, 1st commit 4/2012, 1st private 1/2013, 1st public 10/2013.” HIGHCrowdsourced security as a service put researchers and orgs into at-scale engagement, exactly what made standardized safe-harbor terms necessary by 2014.
Bugcrowd’s “The List”, earliest Wayback capture of a community-maintained public directory of bug-bounty programs (“Last update: 2nd March 2013”). A functional antecedent of diodb (2018) on the directory axis, conceptual only, no documented derivation. MED
Pre-history, disclosure norms (the supply soil)
RFPolicy v1.1 (Rain Forest Puppy) live on wiretrip.net, first formalized vulnerability-disclosure policy template; v2.0 (“5 working days”) followed, bracketed by Wayback snapshots. HIGHGoal: give researchers a repeatable, fair disclosure process.
IETF draft “Responsible Vulnerability Disclosure Process” (Christey/MITRE + Wysopal/@stake), rev 00. HIGHGoal: standardize “responsible disclosure” terminology.
Microsoft (MSRC) reframes “Responsible Disclosure” → “Coordinated Vulnerability Disclosure.” The neutrality pivot between “responsible” (2002) and the ISO-era vocabulary. HIGHGoal: strip the moral judgment out of the terminology.
ISO/IEC 30111 first edition (vulnerability handling processes), the vendor-internal handling standard, published ~3 months before its better-known sibling ISO/IEC 29147. HIGH
ISO/IEC 29147 first edition (vulnerability disclosure). MEDGoal: a formal international standard.
2014, the earliest provenance root (Bugcrowd precursor, not yet a “dioterm”)
Bugcrowd “Standard Disclosure Terms”, platform-wide terms for its programs (in-page changelog: “Initial Release”), carrying researcher-protection intent (“the more closely your behavior follows these rules, the more we’ll be able to protect you”) but no legal safe-harbor clause. An earlier Bugcrowd terms artifact, not the provenance root. HIGH capture / MED release-dayWayback-verified 2014-04-11; the changelog claims a 2014-03-31 initial release.
Google announces Project Zero, 8 days before the root commit; its 90-day disclosure deadline (+14-day grace) is formalized 2015-02-13. The July-2014 disclosure-norms fortnight; conceptual antecedent (dashed). HIGH
bugcrowd/disclosure-policy first commit (10ea3e1, Chris Raethke). Files: responsible_disclosure_policy.md, setting_up_a_responsible_disclosure_program.md. HIGHGoal: an open-source, copy-pasteable disclosure framework with built-in legal safe harbor for researchers.
Launch press (~15h after the commit): PRNewswire “Bugcrowd Releases Open Source Responsible Disclosure Framework” + Threatpost, both pointing at the repo and quoting CipherLaw’s Jim Denaro (“…researchers… are not discouraged from reporting… because of the legal risks”). The git + Wayback + press triangle, closed. HIGH
Earliest Wayback capture of the Bugcrowd framework repo (HTTP 200). HIGH
2017–2018, the legal-safe-harbor idea crystallizes
Amit Elazari’s safe-harbor scholarship begins (DEF CON Skytalks / BSidesLV, unrecorded). MEDGoal: make legal safe harbor a standardized norm, not a per-program favor.
U.S. DOJ Criminal Division publishes “A Framework for a Vulnerability Disclosure Program for Online Systems,” v1.0, prosecutorial guidance for designing VDPs that reduce researcher legal risk. Elazari’s template README credits it. HIGH
CERT/CC publishes The CERT Guide to Coordinated Vulnerability Disclosure (CMU/SEI-2017-SR-022), the canonical CVD handbook. HIGH
Enigma 2018 talk “Hacking the Law: Are Bug Bounties a True Safe Harbor?” HIGH
Dropbox, “Protecting Security Researchers”: the first “‘authorized’ conduct under the CFAA” + DMCA-waiver safe-harbor language in this corpus. HIGH
EdOverflow/legal-bug-bounty templates repo created (README credits Dropbox). HIGH
SSRN paper “Private Ordering Shaping Cybersecurity Policy: The Case of Bug Bounties” (SSRN ID 3161758, no DOI; cite the ID). HIGH
2015–2018, the disclose.io domain's first life (a guidance site + a contact "List")
Before the Aug-2018 safe-harbor relaunch, the disclose.io domain already served a different project. This is brand/domain pre-history, not a dioterms text ancestor, kept together here (slightly out of strict date order) so the domain's own story stays in one place.
Earliest Wayback capture of the disclose.io domain (HTTP 200), a GitHub-Pages site titled “Disclose.io, community-maintained vulnerability disclosure guidance”: researcher legal-risk guidance (CFAA, DMCA, EFF / Rapid7 links) plus a searchable “List” interface backed by an Algolia security_list index for looking up a domain's security-contact aliases. HIGH (capture)Guidance content existed at the domain by 2015-12-11 (captured at /index.html; the relaunched homepage returns 200 only from 2018), ~2.5 years before the terms project, and it is a directory antecedent of diodb / directory.disclose.io on the contact-lookup axis. This is about the domain, not the modern site.
The first-life guidance site is still served, the last archived state before the pivot (previously cited on this page as the domain's “first live content”; the 2015 capture supersedes it). Continuity of ownership/authorship between this 2015–18 incarnation and the Aug-2018 relaunch is unverified, the snapshot shows only that the domain served this content, not who ran it.
2018, disclose.io is born
disclose/diodb first commit (0158e3b), oldest repo in the disclose org. HIGH
disclose.io launches (Bugcrowd + Amit Elazari), explicitly merging the three predecessors. HIGHGoal (2018 launch-day, verbatim): “a collaborative and vendor-agnostic project to standardize best practices around safe harbour for good-faith security research.”
The launch-day Wayback capture already shows the full terms project: “Read the core terms,” all three tributaries named, and “so our hacker friends don’t go to jail.” (Corrects an earlier “first terms capture = 2018-08-29”.) HIGH
ISO/IEC 29147 second edition published (the 2014 first edition withdrawn/superseded), two months after disclose.io’s launch; the standards track and the safe-harbor track converge on the same year. HIGH
diodb’s first real program list: 426 organizations (698675f). HIGHGoal: track who has adopted safe-harbor terms.
2020, the terms get a canonical home + the adoption engine
disclose/dioterms repo first commit (851a906). HIGH
First canonical terms text in the disclose org (be213be, generic-core-terms.md) with an explicit “Safe Harbor” section. HIGH
disclose/diosts (Go security.txt scraper) created, the future adoption engine. HIGH
CISA BOD 20-01 finalized: every U.S. federal civilian agency must publish a VDP. HIGH
Wayback captures the actual dioterms text + the 2020 mission, verbatim: “To drive vulnerability disclosure adoption through safety, simplicity, and standardization.” HIGH
Adoption inflection: the diosts bot auto-imports security.txt-discovered programs, jumping diodb 981 → 3,524 entries in one commit (aee74f1). The spike is automation riding CISA BOD 20-01, not a conference. HIGH
2021–2022, the vision broadens
Casey Ellis states the project’s intent on the record in his #HackerCon talk (@hacknotcrime × @redteamvillage), video published 2021-03-29: vision — “a healthy and ubiquitous internet immune system”; mission — “standardize and promote neighborhood watch for the internet”; and an end-game where the trust seal succeeds by becoming unnecessary (“so standard and so normalized that we don’t really need it anymore”). A founder intent statement (primary source), not a terms artifact. HIGHNames the flywheel the project was built to spin: an org adopts the terms → the directory records it → it earns the seal → the next org sees it and follows.
Supporting-standards repos spin out: dnssecuritytxt (2021-03), policymaker (2021-07). HIGHGoal expands toward an ecosystem.
dioterms licensed CC0-1.0 (public domain): LICENSE added in 365c5f8, the terms become genuinely reusable public infrastructure. HIGHGoal: remove every reuse barrier.
RFC 9116 (security.txt) published; co-author EdOverflow was an early diodb contributor, the two efforts are intertwined. HIGH
Wayback captures the 2022 mission, verbatim: “a cross-industry, vendor-agnostic standardization project for safe harbor best practices… a straightforward maturity model.” HIGH
2021–2024, the surrounding legal landscape (context, not dioterms lineage)
These are parallel developments, not descendants of the dioterms, the safe-harbor norm that disclose.io helped popularize turning up in courts and statutes. No textual derivation is claimed; they are here for context.
Van Buren v. United States (SCOTUS, No. 19-783) narrows the CFAA’s “exceeds authorized access,” reducing, though expressly not settling, the exposure the safe-harbor clause exists to waive (the Court left the researcher question open). HIGH
DOJ revises its CFAA charging policy to “for the first time direct that good-faith security research should not be charged”, the prosecution side adopts the same good-faith norm the private templates had been advancing. HIGH
HackerOne “Gold Standard Safe Harbor”, “a short, broad, easily-understood safe harbor statement that’s simple for customers to adopt” (early adopters: GitLab, KAYAK, Yahoo). A descendant of the standardization idea, it does not cite disclose.io. HIGH
EU NIS2 (Directive (EU) 2022/2555) published; Article 12 (“Coordinated vulnerability disclosure”) requires every Member State to adopt a national CVD policy, the CISA-BOD-20-01 pattern, at EU scale. HIGH
Belgium, among the first EU nations with a broad statutory safe harbor for good-faith research (France’s 2016 Digital Republic Act carried a narrower report-to-ANSSI immunity earlier): the CCB framework “allows any natural or legal person, acting without fraudulent or malicious intent, to investigate and report existing vulnerabilities in… systems located in Belgium.” HIGH
EU Cyber Resilience Act (Reg. (EU) 2024/2847) enters into force, manufacturers of products with digital elements must have “a policy on coordinated vulnerability disclosure”, the CVD norm now surfacing as a market-access requirement. HIGH
Mainstream adoption (one pre-org outlier, shown out of strict order)
U.S. DoD VDP goes always-on (“Hack the Pentagon” was the earlier spring-2016 pilot). HIGHThe largest adopter that predates disclose.io itself, placed here because it belongs to the adoption story, not the founding chronology. NOT evidence the org existed in 2016.
Target 2023-11-03 (f71528c) · Dell 2024-03-10 (ddf2f8e) · a16z 2024-09-28 (6f5b57d) · SIX Group 2025-07-20 (0e8e445), each dated by the diodb commit that added it. HIGH
The rebuilt disclose.io site restates the mission as “make vulnerability disclosure safe, simple, and standardized for everyone”, the 2020 triad, now addressed to “everyone” with five persona on-ramps. HIGH
directory.disclose.io, the hosted diodb front-end (“Search vulnerability disclosure and bug bounty programs”), first Wayback-captured. The capture is an upper bound, not a launch date. MED
| When | Stated goal / mission (verbatim) | Source |
|---|---|---|
| 2014 | (implicit in the framework) “an open-source disclosure policy with legal safe harbor” | bugcrowd/disclosure-policy |
| 2015–2018 (pre-pivot) | “Disclose.io is a community-maintained resource for vulnerability disclosure”, the first-life guidance site + contact “List”, live from 2015-12-11 through Jan 2018, before the terms-project pivot of Aug 2018 | Wayback 2015-12 / 2018-01 |
| 2018 (launch) | “a collaborative and vendor-agnostic project to standardize best practices around safe harbour for good-faith security research” | Wayback 2018-08-02 |
| 2020 | “To drive vulnerability disclosure adoption through safety, simplicity, and standardization” | Wayback 2020-11-15 |
| 2021 (talk) | As articulated by the founder in the 2021 talk (not a site-published mission): vision “a healthy and ubiquitous internet immune system”; mission “standardize and promote neighborhood watch for the internet” — the only first-person, spoken-word source in this table | Ellis, #HackerCon 2021 |
| 2022 | “a cross-industry, vendor-agnostic standardization project for safe harbor best practices… a maturity model” | Wayback 2022-07-14 |
| 2026 | “make vulnerability disclosure safe, simple, and standardized for everyone” | Wayback 2026-06-04 |
The arc: a legal artifact (2014 safe-harbor template) → a community resource/directory (2018) → a standardization project with a maturity model (2020–22).
The safe-harbor clause is the newest part of these policies. Three organizations built it, in order:
2014 · Bugcrowd, the goodwill promise, no statutes HIGH
“If you follow these guidelines… we commit to: Not pursue or support any legal action related to your research.”
2018 · Dropbox, where the legal magic word “authorized” enters (Mar 21, 2018), eight days before Elazari’s template repo, which credits it HIGH
“…we consider actions consistent with the policy as constituting ‘authorized’ conduct under the Computer Fraud and Abuse Act (CFAA)” · “a pledge that we won’t bring a Digital Millennium Copyright Act (DMCA) action…” · “…if a third party initiates legal action, Dropbox will make it clear when a researcher was acting in compliance with the policy (and therefore authorized by us).”
2018 · Elazari #legalbugbounty, standardizes it into a reusable, statute-naming template HIGH
“…‘authorized’ conduct under the Computer Fraud and Abuse Act, the DMCA and applicable anti-hacking laws such as Cal. Penal Code 502(c).”
Its README credits the basis: “…the DOJ guidelines… and some leading policies like Dropbox.”
2020 · dioterms, the parameterized synthesis HIGH
“Authorized concerning any applicable anti-hacking laws, and we will not initiate or support legal action… Authorized concerning any relevant anti-circumvention laws… Exempt from restrictions in our Terms of Service (TOS) and/or Acceptable Usage Policy (AUP)… Lawful, helpful… and conducted in good faith.”
Similarity is not provenance. This is concordance + chronology across the texts actually fetched, not a commit-level “who-typed-what” diff. The order is corroborated by disclose.io’s own “three tributaries” attribution (Bugcrowd framework + Elazari + Dropbox) and Elazari’s explicit Dropbox credit, but generic legalese and parallel drafting are not excluded.
| Feature | RFPolicy ’00 | IETF ’02 | ISO ’14 | Bugcrowd ’14 | Dropbox ’18 | Elazari ’18 | dioterms ’20 |
|---|---|---|---|---|---|---|---|
| Disclosure window | ✓5 days | ✓30 days | ? | ✓90 days | ◐ | – | ✓parameterized |
| Researcher conduct | ✓ | ✓ | ✕ | ✓ | ✓ | – | ✓ |
| Vendor commitments | ◐ | ✓ | ✓ | ✓ | ✓ | – | ✓ |
| Legal safe harbor | ✕disclaims | ✕ | ✕ | ◐goodwill | ✓✓CFAA · DMCA | ✓✓+ Cal. 502 | ✓structured |
| Bilateral structure | ✕ | ◐ | ✕ | ✓ | ✓ | ✓ | ✓ |
| Machine-readable | ✕ | ✕ | ✕ | ✕ | ✕ | ✕ | ✓security.txt |
| Self-label | Full Disclosure | Responsible | Vuln disclosure | Responsible Disc. | VDP | Safe Harbor | VDP / BBP |
Full Disclosure (2000, completeness) → Responsible (2002, process) → Coordinated / CVD (2010–14, neutrality, CERT/CC: “responsible… is a matter of opinion… framed within the values of whoever is using the term”) → Safe Harbor (2017–18, legality). dioterms speaks all four dialects at once.
A disclosure policy started as a threat (“fix it or I publish”), became a protocol, then a brand-neutral standard, then a reusable contract, then a legal shield, and finally a machine-readable, government-mandated interface.
HIGH = git commit hash, GitHub API field, RFC/directive, or verified Wayback snapshot. MED = single/secondary source or non-day-precise date.
Caveats (carried forward, not hidden):
3161758. Its page bot-blocks curl (403) but renders live in a browser.core_terms file, only the repo’s tree listing.10ea3e1 (2014-07-23, Chris Raethke)github.com/bugcrowd/disclosure-policy/commit/10ea3e1…cc83616 (2018-04-04)github.com/bugcrowd/disclosure-policy/commit/cc836160158e3b, 2018-05-16)github.com/disclose/diodb851a906, 2020-06-30)github.com/disclose/dioterms#legalbugbounty, safe_harbor.md template (the standardized clause)github.com/EdOverflow/legal-bug-bounty/…/safe_harbor.mdcore-terms-vdp.md / core-terms-bbp.md (the parameterized synthesis)github.com/disclose/diotermsPeer-reviewed and scholarly works that name or cite disclose.io in their text, from a one-line reference to substantive discussion, evidence of the project's reception in academic and legal literature (distinct from the provenance lineage above). Surfaced via an OpenAlex full-text query plus a targeted PDF sweep; the literal “disclose.io” reference was read and confirmed in each source's open-access full text (retrieved 2026-07-06), and most bug-bounty / CVD papers checked did not mention it, so these are genuine hits. Primary DOI / publisher links given; preprints are pinned to the version read.
policymaker.disclose.io (a U.S. government-association policy paper; literal “disclose.io” ×5)nass.org/…/white-paper-ingalls-nass-summer22.pdfthreats.disclose.ioblog.genlaw.org/pdfs/genlaw_icml2024/39.pdfdisclose.io/programs/arxiv.org/abs/2606.25950disclose.io (Q140450099) and the dioterms (Q140446836) as first-class entities; Crunchbase carries a disclose.io org profile; the Wikipedia “Bugcrowd” article references disclose.io (no standalone article yet)wikidata Q140450099 · Q140446836 · crunchbaseSource project: history.disclose.io · full sources ledger retained alongside the timeline. Published 2026-07-05.