Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

After you submit a private vulnerability report, the receiving organization or platform typically acknowledges it, checks whether it is in scope and reproducible, and decides whether to investigate, request more details, route it to another team, or close it. A report is not automatically confirmed, fixed, made public, or rewarded just because it was submitted. The program’s policy controls confidentiality, disclosure, and any bounty.

What happens to a report after submission?

The details depend on whether you reported directly to an organization, through a bug bounty platform, or to a vulnerability coordinator. The usual stages are similar, but there is no universal timeline or shared set of status labels.

  1. Receipt: Your report enters the channel named in the policy. Some channels send an automated confirmation; others promise a human acknowledgment. For example, get.gov says it will acknowledge a report within three business days if the reporter provides contact information. That commitment applies to get.gov, not every organization. Read the get.gov vulnerability disclosure policy.
  2. Triage and validation: The receiving team checks whether the affected system is in scope, whether the issue can be reproduced, what its realistic impact may be, and whether it needs more information. A coordinator may also check whether the issue is already known or public and whether it falls within that coordinator’s remit. A report can be referred elsewhere or closed if it is out of scope or not actionable.
  3. Investigation and coordination: If the report appears credible, it may be routed to the team responsible for the affected product or service. In CISA’s coordination model, CISA may contact suppliers, seek confirmation, track progress, and help coordinate between the reporter and vendor. Direct-report and platform workflows may involve different teams and steps. See CISA’s coordinated vulnerability disclosure process.
  4. Remediation or mitigation: The organization investigates and works on a fix or other risk-reducing measure. It may ask you to clarify the affected conditions or provide additional evidence. get.gov says it will, to the best of its ability, confirm a vulnerability and communicate remediation steps and delays; this is a policy-specific commitment, not a general service level.
  5. Closure and any reward decision: A platform or organization may close the report after reaching a decision or completing remediation. Closure does not by itself mean the issue will be publicly disclosed. A bounty is possible only where the applicable program offers one and the report meets its rules; awards may be discretionary.

How the reporting route changes the process

The route determines who receives your report first and what that channel is expected to do. A vulnerability disclosure policy (VDP) explains an organization’s reporting channel, scope, and expectations. Coordinated vulnerability disclosure (CVD) is a process for aligning the reporter, affected supplier, and often a coordinator around validation, remediation, and possible public communication. A VDP does not necessarily promise vendor coordination or a public advisory.

Route Who may triage or validate What the channel may do What governs confidentiality, timing, and rewards
Direct organization VDP The organization receiving the report; it may refer the issue if another party is responsible. Receive and assess reports within the policy’s scope. A VDP alone does not necessarily coordinate suppliers or publish an advisory. The organization’s policy sets expectations. Acknowledgment or update commitments apply only if that policy states them. A bounty is not implied.
Third-party bug bounty platform The platform may receive the submission, while the program’s security team assesses the issue under that program’s rules. Provide a reporting channel and, depending on the platform and program, tools for communication or dispute mediation. Platform-wide guidance can be supplemented or superseded by program-specific terms. The program’s bounty and disclosure settings control eligibility and release.
Coordinator-led CVD A coordinator can assess whether the case is actionable and work with the reporter and affected supplier. Coordinate supplier contact and confirmation, track remediation, and potentially prepare public information such as an advisory. The coordinator’s process governs its own actions; supplier responsiveness, risk, and available mitigations can affect timing. CISA’s process is one particular model, not a deadline for private bug bounty reports.

For HackerOne reports, its guidelines say reports initially remain non-public to give the security team time to remediate. Later disclosure depends on the program’s settings, and some private programs require confidentiality. Review HackerOne’s disclosure guidelines alongside the individual program terms.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Why a report may be delayed, referred, or closed

  • It is outside the stated scope: The affected asset or activity may not be covered by the policy or program.
  • The issue cannot be reproduced: The report may lack enough detail to verify the behavior, or the receiving team may not be able to reproduce it in the described conditions.
  • The issue is already known or not actionable for that channel: A coordinator may determine that it is already public, belongs with another organization, or cannot be handled through that process.
  • The impact or remediation is complex: The organization may need time to assess affected versions, coordinate with a supplier, or prepare a safe mitigation. No single fix deadline applies to all private reports.
  • The organization is not responsive: In CISA’s process, disclosure timing can depend on supplier responsiveness, exploitation status, impact, and available mitigations. CISA says disclosure may occur as early as 45 days after first contact when a vendor is unresponsive or will not set a reasonable remediation timeframe. This is a conditional description of CISA’s process, not a universal rule.

What you should do while the report is being reviewed

  1. Read the applicable rules: Check scope, rules of engagement, confidentiality terms, and disclosure settings before testing or reporting. Program-specific terms matter even when a platform has general guidance.
  2. Make the report verifiable: Include the affected system and conditions, concise reproduction steps, and a realistic explanation of impact. Add relevant proof-of-concept material, but do not include unrelated sensitive data. The HackerOne post-submission guide also recommends clear reproduction information; its June 16, 2026 guide notes that timelines vary.
  3. Stay within authorized testing: Follow the policy’s limits and stop if you encounter sensitive data or have established the issue. get.gov specifically prohibits using exploits to access or extract data, persist, pivot, or disrupt services.
  4. Reply through the designated channel: Answer reasonable clarification requests and keep report-related communication in the required thread or contact path. On HackerOne, the guide recommends keeping related communication on the platform.
  5. Wait for permission before disclosure: A fix, report closure, or lack of updates does not automatically authorize public disclosure. Check the program’s rules and obtain any approval they require.

What acknowledgment, privacy, and payment do—and do not—mean

  • An acknowledgment confirms receipt, not validity. The issue still needs assessment and may be referred, declined, or found non-reproducible.
  • “Private” is policy-dependent. A report may be kept non-public during remediation, but the governing policy or program terms determine who can see it and whether it can later be disclosed.
  • A bounty is not automatic. Some teams offer rewards, while others do not. Payment depends on the program’s eligibility rules and decision; submission alone does not create a guaranteed award.
  • Disclosure is a separate decision. A coordinated case may eventually lead to a public advisory, but not every report follows that route. CISA’s process can include a CVE-record decision and advisory preparation; that does not mean every private report receives a CVE or becomes public.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.