Wiz Research · Scan for Good · Policy
How Wiz Research handles vulnerabilities found through Scan for Good.
Last updated August 27, 2026
scanforgood@wiz.io
This policy applies to vulnerabilities found by Wiz Research through Scan for Good in open-source software and in systems where testing is authorized.
It does not cover external reports about Wiz products or infrastructure, which follow Wiz's separate responsible-disclosure process.
Testing is limited to:
A public website, application, nomination, or security.txt record does not by itself authorize testing.
Our default is the Project Zero 90+30 model: up to 90 days to make a patch or effective mitigation available, followed by 30 days before detailed publication when a fix is released within that period.
A 14-day grace period may be granted when a fix is expected shortly after the deadline. For vulnerabilities credibly exploited in the wild, the target is 7 days, with a possible 3-day grace period.
We may agree to earlier disclosure or adjust a deadline for broad ecosystem impact, remediation complexity, existing public knowledge, or another material security reason.
Testing remains inside the authorized scope and stops after the minimum evidence needed to explain the issue.
Traffic identifiers and opt-out controls are published on the scanning-transparency page.
Before remediation and the applicable disclosure period, public information is limited to generalized, non-exploitable material. We do not publish credentials, personal information, or details that identify or enable exploitation of an unresolved target.
Naming an organization requires separate approval. Publication approval is not a condition of Scan for Good support.
Use this address to respond to a report, coordinate remediation, request a timeline adjustment, or raise a concern about Scan for Good activity.