Skip to content
Coordinated vulnerability disclosure

Responsible vulnerability research for a safer open-source ecosystem.

We study the software the world depends on, report what we find privately to the people who maintain it, and keep anything sensitive under embargo until there is a fix.

Our approach

A small set of principles we don't bend.

Embargo Lab exists to make widely-used software safer without putting its users at risk along the way. How we work follows from that.

Depth over noise

We read code closely and confirm a finding before we ever raise it. No automated dumps, no speculative reports — only issues we understand and can substantiate.

Coordinated disclosure

We report privately to the people who maintain the software first, and work with them toward a fix. Maintainers are partners, not adversaries.

Embargo discipline

Nothing sensitive is published before a fix is available or an agreed disclosure window has passed. The name on the door is a promise about timing.

Credit where due

We acknowledge the maintainers who fix issues and the researchers who find them, and we welcome the same courtesy in return.

Found a vulnerability? We'll handle it responsibly.

We follow coordinated disclosure in both directions: we report what we find under embargo, and we welcome good-faith reports under the same terms. Our policy explains how to reach us, what to include, and what you can expect back.

Disclosure

Get in touch.

For security reports, coordination, or general enquiries — we read everything.