-
Vulnerability Disclosure Policy (VDP) template
-
A process to report security vulnerabilities
-
Document dependencies and libraries used
-
Share data with EU authorities
-
Notify users about vulnerability exploits
-
Provide security updates (separately)
Patchstack helps with patch validation
Ship more secure code, faster
Security and compliance platform for open-source vendors
Patchstack's managed VDP (mVDP) acts as an expert intermediary and streamlines vulnerability disclosure for plugin and theme developers.
| Comparison | mVDP by Patchstack | In-house VDP |
|---|---|---|
| Cost | Free | Tools and staff (security analyst) |
| Implementation | 15 minutes | Process development takes time |
| Compliance | Pre-built compliance with CRA, ISO/IEC 29147, GDPR in mind | Requires expertise (compliance officer) and time to research legalities |
| Talent | Patchstack runs the most active open-source bug bounty program and a top-tier triage team | Security researchers are difficult to attract, motivate and manage |
| Threat Intelligence | Continuous 24/7 processing of incoming data, along with intelligence from third-party data sources | Additional operational burden and limited due to lack of monitoring in distributed software |
| Quality | Fully filtered and valid reports with commentary from the triage team | High percentage of false, incomplete and meaningless “beg bounty” reports |
| Vulnerability processing | Patchstack is the worlds’ largest handler of vulnerability data (CNA) | Obtaining a CNA status to disclose vulnerabilities requires resources |
| Disclosure and handling | Patchstack manages legal complexities and coordinates disclosure via best industry practices | Higher legal risks due to lack of expertise, and additional operational burden |
Take your code security to the next level and partner with the leader in open-source security
Managed VDP
No CC required
Security programs
Streamline your disclosure process to fix security vulnerabilities faster and comply with emerging regulations.
Start a managed VDP for free- 1 seat
- Vulnerability validation
- CVE coordination
- Patch validation
- AXP boost +25% to motivate researchers
- Follow CRA, ISO/IEC 29147, GDPR guidelines
- Embeddable reporting form
"We highly recommend Patchstack to other companies looking to enhance their security posture. For us, Patchstack is a true partner in our security efforts, and we're more than satisfied with their services."
Miriam Schwab
Head of WordPress Relations
Security disclosure and CRA compliance with Patchstack
In Q4 2024, The Cyber Resilience Act (CRA) introduced obligatory software support and vulnerability disclosure guidelines for all commercial software with users in the European Union.
Patchstack solves this by acting as an expert intermediary and streamlines vulnerability disclosure for plugin and theme developers.