Why Vulnerability Disclosure Policies Need Researcher Protections

Dropbox runs a bug bounty program with industry-leading rewards, and we periodically issue retroactive bonus payments for particularly clever or high-impact findings. But a bounty program is only part of the picture. The foundation underneath it is the Vulnerability Disclosure Policy (VDP) — and it's possible to have a strong VDP without any bounty at all. Organizations should start their security work there.

Open security research has historically faced legal threats, lawsuits, referrals to authorities, and public attacks on researchers' character and motivations. Vague laws have been used to criminalize good-faith research, and researchers have been pressured or even fired through abuses of legal and business relationships. That matters because much of the progress in security comes from the combined work of the independent research community.

Looking at our own VDP, we saw room to improve. Our updated policy now includes specific commitments:

  • A clear statement welcoming external security research
  • A pledge not to initiate legal action for research conducted under the policy, including good-faith accidental violations
  • An explicit statement that policy-compliant conduct constitutes authorized activity under the Computer Fraud and Abuse Act (CFAA)
  • A pledge not to bring a Digital Millennium Copyright Act (DMCA) action against researchers acting in compliance with the policy
  • A commitment to clarify when a researcher was acting in compliance if a third party initiates legal action
  • A statement that we don't negotiate bounties under duress — researchers should report findings immediately with no conditions attached
  • Guidance on what to do if a researcher inadvertently encounters data belonging to someone else
  • A request for reasonable time to fix issues before public disclosure — we don't reserve the right to take indefinitely long

One thing our VDP deliberately does not include is any gate on publishing vulnerability details. Using policy or bounty payments to muzzle or curate scientific publication would be inappropriate.

The full text of our VDP is freely copyable as a template. We put significant effort into it across our legal and security teams, and we hope others will adopt a similar approach. We're also open to suggested improvements.

A formal policy alone isn't enough, of course. Treating researchers with respect matters just as much. That means prompt responses, fast payouts, transparency, and direct conversations with our security engineers. For top bug bounty participants, we also host office visits and talks and occasionally set up special internal contracts.

We referenced HackerOne's VDP guidelines, the US Department of Justice Cyber Security unit's VDP framework, and recent Senate testimony on vulnerability disclosure when refreshing our policy.

We're also extending these expectations to our suppliers. Going forward, we'll take an unfavorable view of potential vendors that lack researcher-protective VDPs or have no VDP at all. A missing or restrictive disclosure policy is often a sign of poor security. A welcoming policy with strong researcher protections usually indicates a mature security posture.

We value the open security research community, and we've taken concrete steps to protect the people in it. We expect any company that treats security as a priority to do the same.