ivx research

ivx research Disclosure

Disclosure

sourcegetting startedarchitectureconfiguration

Disclosure removes the middleman from vulnerability disclosure. Security researchers report vulnerabilities directly to vendors, end-to-end encrypted. No platform fees. No gatekeepers. Vendors run their own programs on their own infrastructure. Researchers and vendors find each other through federation.

Key features

  • End-to-end encryption — Report content is encrypted before it leaves the researcher's browser. Only the vendor can decrypt it. Not even the server admin can read it.
  • Self-hosted — Run it on your own infrastructure. Your data, your rules.
  • Federated — Instances can discover each other and exchange reports through ActivityPub, similar to how Mastodon instances federate.
  • No platform fees — No middleman taking a cut. Researchers and vendors deal directly.
  • Open source — Fully open source under a permissive license. Audit it, fork it, contribute to it.

Status

Disclosure is in alpha. It's functional but not yet production-ready. We're actively developing it and welcome feedback and contributions.

Documentation

Getting Started

Install Disclosure from source, create an account and run the server.

Architecture

How the server, the ActivityPub federation layer and the end-to-end encryption fit together.

Configuration

Every configuration key, environment variable and CLI command.