Skip to content

ECHOS / Policy · v0.1 · July 2026

Coordinated Disclosure Policy

How Botzr Research discloses vulnerabilities it finds, and how to report vulnerabilities in the lab's own code. The version at this URL is authoritative; a machine-readable summary lives at /.well-known/security.txt.

When we find a vulnerability

  • The maintainer or vendor is contacted privately first, with a reproducible report.
  • Where the vendor runs a bounty program, the report goes through it and follows its rules, including its disclosure terms. Where none exists, we report directly and expect nothing in return.
  • Advisories route through GHSA and CVE rather than through blog posts or social media.
  • The default embargo is 90 days from first report. It extends when a fix is genuinely underway and shortens only if the issue is being actively exploited.
  • The target is not named publicly before the advisory publishes. No exceptions, including hints.
  • Maintainers who fix issues are credited in the advisory unless they prefer otherwise.

Reporting a vulnerability to us

  • Email help@botzr.com with ECHOS in the subject line. Those get read first.
  • You will get a human acknowledgment within 72 hours.
  • We do not run a bounty program for our own code; nothing is for sale here. What we offer is a fast response, credit, and a fix.

Safe harbor

Good-faith security research against the lab's published code will not be met with legal action. Good faith means: no data exfiltration beyond proof of concept, no degradation of service for others, and private reporting before publication.