Vulnerability Disclosure Policy

Owner: Security. Review cadence: annual or on material change.

MeterBox welcomes reports from security researchers. This policy is the public-facing program description — the text to paste into a HackerOne (or similar) private program and to link from /.well-known/security.txt.

Reporting

Scope

In scope:

Out of scope (report to the upstream instead):

Safe harbor

We will not pursue legal action against good-faith research that:

Good-faith research conducted under this policy is authorized; we consider it neither a violation of our terms nor of anti-hacking law.

Our commitments

Operationalization (the human steps)

This document is the policy; standing up the managed program is an organizational action that can't be automated. The detailed program structure — reward tiers, eligibility, duplicate handling, phase graduation — lives in the bug bounty program doc. Summary:

  1. Create the HackerOne program (private/invite-only to start), paste this policy as the program brief, paste the bug-bounty program doc (minus its § 8) as the private brief, set scope from the lists above.
  2. Fund the bounty pool per bug-bounty-program.md § 2 reward tiers; CEO sets quarterly budget.
  3. Point /.well-known/security.txt (served by the control plane) at the program URL once it exists — update the Policy/Contact fields.
  4. Route HackerOne reports into the same triage + remediation-SLA workflow as CI/Dependabot findings.

Related docs