> Source: https://botzr.com/echos/policy
> Part of Botzr Research — https://botzr.com
> Last updated: 2026-08-11

ECHOS / Policy · v0.1 · July 2026

# Coordinated Disclosure Policy

How Botzr Research discloses vulnerabilities it finds, and how to report vulnerabilities in the lab's own code. The version at this URL is authoritative; a machine-readable summary lives at [/.well-known/security.txt](https://botzr.com/.well-known/security.txt).

## When we find a vulnerability

- The maintainer or vendor is contacted privately first, with a reproducible report.
- Where the vendor runs a bounty program, the report goes through it and follows its rules, including its disclosure terms. Where none exists, we report directly and expect nothing in return.
- Advisories route through GHSA and CVE rather than through blog posts or social media.
- The default embargo is **90 days** from first report. It extends when a fix is genuinely underway and shortens only if the issue is being actively exploited.
- The target is not named publicly before the advisory publishes. No exceptions, including hints.
- Maintainers who fix issues are credited in the advisory unless they prefer otherwise.

## Reporting a vulnerability to us

- Email [help@botzr.com](mailto:help@botzr.com) with **ECHOS** in the subject line. Those get read first.
- You will get a human acknowledgment within 72 hours.
- We do not run a bounty program for our own code; nothing is for sale here. What we offer is a fast response, credit, and a fix.

## Safe harbor

Good-faith security research against the lab's published code will not be met with legal action. Good faith means: no data exfiltration beyond proof of concept, no degradation of service for others, and private reporting before publication.

[The ECHOS program](https://botzr.com/programs/echos) [Contact](https://botzr.com/contact)
