Sentinel runs coordinated disclosure. Findings stay private while the program fixes them, then become public on a schedule both sides know in advance. The default window is 90 days from triage.
Default timeline
Day 0 is the moment the report enters Triaged, not the moment you submitted it.
| Milestone | Target | Meaning |
|---|---|---|
| First human response | 3 business days from submission | A triager has read the report |
| Triage decision | 7 business days from submission | Accepted with a severity, or closed with a reason |
| Reward decision | 14 days from Triaged |
Bounty set and paid, independent of the fix |
| Fix window | 90 days from Triaged |
Program ships and verifies a fix |
| Public disclosure | Day 90, or on Resolved if earlier |
Report becomes public |
| Researcher publication | Day 90 onward | You may publish your own write-up |
Most programs publish as soon as the fix is verified, so many reports disclose well before day 90.
Extensions
A program may request more time when a fix is genuinely in flight:
- The request must arrive before day 75 and name a target date and reason, such as a coordinated multi-vendor release.
- One extension of up to 30 days is granted on request, taking the window to 120 days.
- Further extensions need your written agreement in the thread. If you decline, the window stands.
- A request with no target date is not an extension request, and the timeline continues.
You can agree to hold longer than the policy requires. Say so in the thread so the date is on the record, rather than reconstructing it from memory six months later.
Who may publish, and what to redact
After the window closes, either party may publish. Both follow the same rules:
- Remove user data. Names, emails, tokens, record contents, internal ticket IDs, anything identifying a person.
- Remove credentials and secrets, including API keys captured during testing.
- Hold working exploit code back when the fix shipped less than 30 days ago and the bug is unauthenticated and remote. A redacted proof of concept is fine.
- Leave out infrastructure details such as internal hostnames and IP ranges unless the program agrees.
The program publishes the report on its Sentinel page. You may publish a write-up anywhere, and linking back is encouraged. Neither side should publish claims about the other's conduct in a technical write-up; take those to mediation.
Actively exploited in the wild
If either party finds credible evidence of in-the-wild exploitation, the standard timeline is replaced:
- Flag the report
Exploited in the wildwith the evidence. This pages the program's security contact. - The program has 7 days to ship a fix or publish a mitigation users can act on.
- Disclosure follows at day 14, with or without a complete fix, because users already at risk need to know.
- Extensions do not apply. A partial mitigation published on time satisfies step 2.
This path exists for evidence of real exploitation, not for a bug that is merely easy to exploit.
CVE assignment
Sentinel requests CVE IDs for vulnerabilities in distributed or self-hosted software: libraries, agents, firmware, installable applications. A bug confined to a first-party hosted service normally gets no CVE, because there is no version for users to act on.
- Either party may request assignment in the thread. Sentinel files when the program is not itself a CNA.
- You are listed as reporter unless you ask to stay anonymous.
- The ID is reserved at request and published at disclosure, so a CVE does not shorten the window.
- The record uses the triaged CVSS v3.1 vector described in severity and rewards.
When a program goes unresponsive
Timelines assume someone is reading. When nobody is:
- No response for 14 days: use "Nudge program". Sentinel emails the program's escalation contact.
- No response for 30 days: request mediation. A mediator contacts the program and posts the outcome in the thread.
- No response for 30 days after mediation opens: the report is marked
Unresponsive program, a badge appears on its entry in the directory, and disclosure proceeds at day 90 with a note that the program never engaged. - A program unresponsive on multiple reports can be delisted. Existing reports keep their safe harbor, which survives delisting.
Unresponsiveness does not let you publish early. The 90 day floor holds, with the single exception of the in-the-wild path above. If you are unsure where a report stands, ask in the thread before you publish. See report quality for keeping the record clear, and getting started for how a report reaches Triaged.