Install Disclosure from source, create an account and run the server.
ivx research Disclosure
Disclosure
Disclosure removes the middleman from vulnerability disclosure. Security researchers report vulnerabilities directly to vendors, end-to-end encrypted. No platform fees. No gatekeepers. Vendors run their own programs on their own infrastructure. Researchers and vendors find each other through federation.
Key features
- End-to-end encryption — Report content is encrypted before it leaves the researcher's browser. Only the vendor can decrypt it. Not even the server admin can read it.
- Self-hosted — Run it on your own infrastructure. Your data, your rules.
- Federated — Instances can discover each other and exchange reports through ActivityPub, similar to how Mastodon instances federate.
- No platform fees — No middleman taking a cut. Researchers and vendors deal directly.
- Open source — Fully open source under a permissive license. Audit it, fork it, contribute to it.
Status
Disclosure is in alpha. It's functional but not yet production-ready. We're actively developing it and welcome feedback and contributions.
Documentation
How the server, the ActivityPub federation layer and the end-to-end encryption fit together.
Every configuration key, environment variable and CLI command.