ECHOS / Policy · v0.1 · July 2026
Coordinated Disclosure Policy
How Botzr Research discloses vulnerabilities it finds, and how to report vulnerabilities in the lab's own code. The version at this URL is authoritative; a machine-readable summary lives at /.well-known/security.txt.
When we find a vulnerability
- The maintainer or vendor is contacted privately first, with a reproducible report.
- Where the vendor runs a bounty program, the report goes through it and follows its rules, including its disclosure terms. Where none exists, we report directly and expect nothing in return.
- Advisories route through GHSA and CVE rather than through blog posts or social media.
- The default embargo is 90 days from first report. It extends when a fix is genuinely underway and shortens only if the issue is being actively exploited.
- The target is not named publicly before the advisory publishes. No exceptions, including hints.
- Maintainers who fix issues are credited in the advisory unless they prefer otherwise.
Reporting a vulnerability to us
- Email help@botzr.com with ECHOS in the subject line. Those get read first.
- You will get a human acknowledgment within 72 hours.
- We do not run a bounty program for our own code; nothing is for sale here. What we offer is a fast response, credit, and a fix.
Safe harbor
Good-faith security research against the lab's published code will not be met with legal action. Good faith means: no data exfiltration beyond proof of concept, no degradation of service for others, and private reporting before publication.