Wiz Research · Scan for Good · Policy

Coordinated vulnerability disclosure

How Wiz Research handles vulnerabilities found through Scan for Good.

Last updated August 27, 2026
scanforgood@wiz.io

Purpose and scope

This policy applies to vulnerabilities found by Wiz Research through Scan for Good in open-source software and in systems where testing is authorized.

It does not cover external reports about Wiz products or infrastructure, which follow Wiz's separate responsible-disclosure process.

Authorization

Testing is limited to:

  • systems covered by explicit written authorization;
  • targets and techniques clearly permitted by an applicable bug-bounty or vulnerability-disclosure policy; or
  • work coordinated with an authorized asset owner, CERT, or public authority.

A public website, application, nomination, or security.txt record does not by itself authorize testing.

Validation and reporting

  • Wiz Research reviews and reproduces a candidate before it is reported.
  • Reports are sent privately to the affected organization or an appropriate coordinator.
  • Reports include the affected scope, evidence, safely proven impact, stopping point, and remediation guidance.
  • AI-assisted findings are identified as such.
  • Critical issues and evidence of active exploitation are escalated promptly.

Disclosure timeline

Our default is the Project Zero 90+30 model: up to 90 days to make a patch or effective mitigation available, followed by 30 days before detailed publication when a fix is released within that period.

A 14-day grace period may be granted when a fix is expected shortly after the deadline. For vulnerabilities credibly exploited in the wild, the target is 7 days, with a possible 3-day grace period.

We may agree to earlier disclosure or adjust a deadline for broad ecosystem impact, remediation complexity, existing public knowledge, or another material security reason.

Validation boundaries

Testing remains inside the authorized scope and stops after the minimum evidence needed to explain the issue.

  • Read-only validation is the default.
  • No denial of service, destructive testing, persistence, or unnecessary data collection.
  • Controlled writes require explicit authorization and human approval.
  • Testing stops at third-party or otherwise out-of-scope systems.

Traffic identifiers and opt-out controls are published on the scanning-transparency page.

Publication

Before remediation and the applicable disclosure period, public information is limited to generalized, non-exploitable material. We do not publish credentials, personal information, or details that identify or enable exploitation of an unresolved target.

Naming an organization requires separate approval. Publication approval is not a condition of Scan for Good support.

Contact

scanforgood@wiz.io

Use this address to respond to a report, coordinate remediation, request a timeline adjustment, or raise a concern about Scan for Good activity.