Coordinated disclosure policy

The 90 day default window, how extensions work, who may publish what, CVE assignment, and what happens when a program stops responding.

Last updated 18 Sep 2026 · 18 days ago

Sentinel runs coordinated disclosure. Findings stay private while the program fixes them, then become public on a schedule both sides know in advance. The default window is 90 days from triage.

Default timeline

Day 0 is the moment the report enters Triaged, not the moment you submitted it.

Milestone Target Meaning
First human response 3 business days from submission A triager has read the report
Triage decision 7 business days from submission Accepted with a severity, or closed with a reason
Reward decision 14 days from Triaged Bounty set and paid, independent of the fix
Fix window 90 days from Triaged Program ships and verifies a fix
Public disclosure Day 90, or on Resolved if earlier Report becomes public
Researcher publication Day 90 onward You may publish your own write-up

Most programs publish as soon as the fix is verified, so many reports disclose well before day 90.

Extensions

A program may request more time when a fix is genuinely in flight:

  • The request must arrive before day 75 and name a target date and reason, such as a coordinated multi-vendor release.
  • One extension of up to 30 days is granted on request, taking the window to 120 days.
  • Further extensions need your written agreement in the thread. If you decline, the window stands.
  • A request with no target date is not an extension request, and the timeline continues.

You can agree to hold longer than the policy requires. Say so in the thread so the date is on the record, rather than reconstructing it from memory six months later.

Who may publish, and what to redact

After the window closes, either party may publish. Both follow the same rules:

  • Remove user data. Names, emails, tokens, record contents, internal ticket IDs, anything identifying a person.
  • Remove credentials and secrets, including API keys captured during testing.
  • Hold working exploit code back when the fix shipped less than 30 days ago and the bug is unauthenticated and remote. A redacted proof of concept is fine.
  • Leave out infrastructure details such as internal hostnames and IP ranges unless the program agrees.

The program publishes the report on its Sentinel page. You may publish a write-up anywhere, and linking back is encouraged. Neither side should publish claims about the other's conduct in a technical write-up; take those to mediation.

Actively exploited in the wild

If either party finds credible evidence of in-the-wild exploitation, the standard timeline is replaced:

  1. Flag the report Exploited in the wild with the evidence. This pages the program's security contact.
  2. The program has 7 days to ship a fix or publish a mitigation users can act on.
  3. Disclosure follows at day 14, with or without a complete fix, because users already at risk need to know.
  4. Extensions do not apply. A partial mitigation published on time satisfies step 2.

This path exists for evidence of real exploitation, not for a bug that is merely easy to exploit.

CVE assignment

Sentinel requests CVE IDs for vulnerabilities in distributed or self-hosted software: libraries, agents, firmware, installable applications. A bug confined to a first-party hosted service normally gets no CVE, because there is no version for users to act on.

  • Either party may request assignment in the thread. Sentinel files when the program is not itself a CNA.
  • You are listed as reporter unless you ask to stay anonymous.
  • The ID is reserved at request and published at disclosure, so a CVE does not shorten the window.
  • The record uses the triaged CVSS v3.1 vector described in severity and rewards.

When a program goes unresponsive

Timelines assume someone is reading. When nobody is:

  1. No response for 14 days: use "Nudge program". Sentinel emails the program's escalation contact.
  2. No response for 30 days: request mediation. A mediator contacts the program and posts the outcome in the thread.
  3. No response for 30 days after mediation opens: the report is marked Unresponsive program, a badge appears on its entry in the directory, and disclosure proceeds at day 90 with a note that the program never engaged.
  4. A program unresponsive on multiple reports can be delisted. Existing reports keep their safe harbor, which survives delisting.

Unresponsiveness does not let you publish early. The 90 day floor holds, with the single exception of the in-the-wild path above. If you are unsure where a report stands, ask in the thread before you publish. See report quality for keeping the record clear, and getting started for how a report reaches Triaged.