TILLSHIELD · DISCLOSURE

A front door for security researchers.

Beta

A disclosure program is a public page where anyone who finds a vulnerability in what you run can tell you about it: your policy, what is in scope, safe harbor, rewards, and how quickly you answer. Reports arrive in a private inbox under Shield → Disclosures, sealed with your workspace’s data key, with a clock for your first reply and one for your decision. The program also writes the security.txt that points researchers and their tools to it.

01Start

Set up the program

Under Shield → Disclosures → Program, give the program a name, list at least one asset in scope, write your policy and turn on Take reports. The page is at tilldev.dev/disclose/<handle>; the handle starts as your workspace’s and can be changed. Only owners and admins see reports or change the program. From the CLI:

sh
tilldev shield disclosures program set --name "Acme" --in-scope acme.com,api.acme.com --domains acme.com --enable
tilldev shield disclosures program security-txt > .well-known/security.txt
tilldev shield disclosures program check                   # exits 1 unless each domain points here
tilldev shield disclosures                                 # open reports, newest first
tilldev shield disclosures show 12
tilldev shield disclosures reply 12 "Thanks, we can reproduce it."
tilldev shield disclosures move 12 accepted                # or resolved, duplicate --duplicate-of 9, informative, not-applicable, spam
tilldev shield disclosures rewards 12 propose 500 USD
02Public page

What researchers see

The page shows the program’s name and your workspace’s, your policy as plain text, what is in and out of scope with a note for each, your reply and decision promises, how long after a fix a researcher may publish, and, when they are on, safe harbor and the reward range for each level. Nothing else about the workspace is shown. A program that is off, or in a suspended workspace, answers as if it doesn’t exist.

With the thanks page on, /disclose/<handle>/thanks lists the names researchers asked to be credited by, for accepted and resolved reports, by month. It never says what they found.

03Reports

Sending a report

The form asks for a title, what they found, and an email address; the asset, a suggested level, a CVSS 3.1 vector, steps to reproduce, impact and a name to be thanked by are optional. It takes plain text only, up to 65,536 characters in all, and no attachments. Before it sends, the browser solves a small proof of work (16 bits of SHA-256) on a challenge that lasts 10 minutes and works once.

A report then waits, unseen by anyone, until the researcher opens the link we email them. That proves the address is theirs, and keeps reports someone else typed an address into out of your inbox. Reports nobody confirms are deleted after 7 days.

05Triage

States, clocks and levels

StateMeansCan move to
NewConfirmed by the reporter and in the inboxTriaging, Accepted, Duplicate, Informative, Not applicable, Spam
TriagingSomeone is looking into itNew, Accepted, Duplicate, Informative, Not applicable, Spam
AcceptedA real vulnerability; it joins the inventoryTriaging, Resolved, Duplicate, Informative, Not applicable
ResolvedFixed; the publication date is setAccepted
DuplicateAnother report came first; it names whichTriaging
InformativeRead, with no action to takeTriaging
Not applicableNot a vulnerability, or out of scopeTriaging
SpamClosed without telling the reporterTriaging
WithdrawnThe reporter closed itNone

Two clocks start when the reporter confirms: a first reply within 3 days and a decision within 10, unless the program says otherwise (1 to 90). Your first reply, or any move, stops the first; a decision is a move to Accepted, Resolved, Duplicate, Informative, Not applicable or Spam. A clock is due soon in its last quarter, and never less than half a day before.

Set the level yourself, or paste a CVSS 3.1 base vector and the level follows its score. A report accepted without a level takes the one the reporter suggested. Every move except Spam emails the reporter a link, and a reason you give is shown to them. Notes are seen only by the team.

06Inventory

Accepted reports in Vulnerabilities

An accepted report joins the vulnerability inventory as a Disclosures item with its level, an owner and a fix-by date. It closes as fixed when the report is resolved, and closes too if the report moves out of Accepted any other way. Like TillDrill items, its risk can be accepted in the inventory, with a reason and an end date.

07Rewards

Rewards

With rewards on, the page lists a range per level in one currency. On an accepted or resolved report, a reward is proposed, approved, then recorded as paid with an optional reference, or cancelled. The researcher sees it once it is approved. TillDev records rewards and moves no money; pay through your own process.

08Alerts

New reports and replies

When a report is confirmed, or a researcher replies, the workspace’s security alerts hear about it once: email, Slack or the signed webhook set under Playbooks & security alerts. An alert carries the report numbers, the asset and the level the researcher gave, and a link. The report itself is never sent. The webhook body:

json
{
  "type": "tillshield.disclosure.received",
  "delivery_id": "5b7e2c1a-…",
  "program": "Acme",
  "reports": [
    { "number": 12, "asset": "api.acme.com", "suggested_level": "high", "at": "2026-10-06T09:12:00.000Z" }
  ],
  "total": 1,
  "checked_at": "2026-10-06T09:13:04.000Z",
  "link": "https://tilldev.dev/acme/shield/disclosures"
}

A reply alert has the type tillshield.disclosure.reply and the same fields.

09security.txt

security.txt

The program writes an RFC 9116 security.txt that points to its page. Serve it at /.well-known/security.txt on each domain you list, or redirect that path to the hosted copy at /disclose/<handle>/security.txt, which stays current. Its Expires date is the first of the month eleven months out, inside the year the RFC allows, so a copied file needs copying again before then.

text
Contact: https://tilldev.dev/disclose/acme
Contact: mailto:security@acme.com
Expires: 2027-09-01T00:00:00.000Z
Encryption: https://acme.com/pgp-key.txt
Acknowledgments: https://tilldev.dev/disclose/acme/thanks
Preferred-Languages: en, fr
Canonical: https://acme.com/.well-known/security.txt
Policy: https://tilldev.dev/disclose/acme

Check my domains reads the file on each domain over https, following up to three redirects and never to a name that resolves to a private address, and reports a missing or expired file, missing fields, a Canonical that doesn’t match, or a Contact that doesn’t point to this program. It can run 10 times an hour.

10Encryption

How reports are kept

The title, the report, the reporter’s address, their link’s secret and every message are sealed with AES-256-GCM under a key derived from your workspace’s data key for that report and that field, so a sealed value can’t be moved to another report or field. A link is found by a hash of its secret. Rotating the workspace data key re-seals every report; the cryptography inventory lists this use. The asset, levels, CVSS vector and credit name are kept in the clear so the inbox can filter and the thanks page can list them.

Owners and admins
Reading reports, triage, rewards and the program take an owner or admin. Every action is in the audit log.
11Limits

Limits

WhatLimit
Reports from one network5 an hour
Reports to one program60 an hour
Reports from one address10 a day to a program, 20 a day in all
Replies on a report30 an hour; 500 messages in all
A reporttitle 5 to 200 characters; 65,536 characters in all
A message20,000 characters
Scope50 assets in and 50 out
Domains for security.txt10
Publication after a fix0 to 365 days, 90 unless set
A rewardup to 1,000,000 in the program’s currency

The API is under /api/v1/shield/disclosures for the team and /api/v1/disclose for researchers, in the API reference.