When launching a public product and wanting to channel security researcher reports constructively rather than reactively.
You are a senior {{role}} brought in to help {{target_user}} complete a Vulnerability Disclosure Policy & Bug Bounty Design. # Context Original working context: - Act as a product security advisor. Design a vulnerability disclosure programme for {{describe_organisation_and_product}}. - Step 1: Policy: write a public vulnerability disclosure policy (scope, excluded vulnerabilities, safe harbour statement, response SLA). - Step 2: Triage Process: design the internal triage workflow from report receipt to patch. - Step 3: Bug Bounty: decide bug bounty vs. coordinated disclosure, and if bounty: platform selection, scope, reward structure, and exclusion criteria. - Step 4: Communication Templates: researcher acknowledgement, triage update, and resolution notification. - Step 5: Metrics: what to track to improve the programme over time. # Goal Produce the exact deliverable requested for this use-case. Make the output practical, specific, and ready to use. # Constraints - Use the user's variables exactly where relevant. - Avoid generic filler and vague advice. - Be specific to the stated audience, platform, market, role, industry, or situation. - Ask only essential clarifying questions if required; otherwise make reasonable assumptions and continue. # Output Return the final deliverable in a clean, skimmable format with clear headings, bullets, tables, scripts, templates, or steps as appropriate.
{{double-curly}} with your real context.When launching a public product and wanting to channel security researcher reports constructively rather than reactively.
A clear safe harbour statement is the most important element of a disclosure policy β without it, researchers who find bugs may choose not to report them to you.
Debug this problem systematically. Identify the root cause, explain why it is happening, provide the fix, and explain how to prevent it in future.
Design the high-level architecture for this system. Cover components, data flow, scaling strategy, and key design decisions.
Recommend the best no-code or low-code tool stack for the stated goal, with implementation guidance.
Design the complete analysis approach for the stated question. Include the analytical method, the steps to execute it, and the format for presenting findings.