July 31, 2026
Found a Security Vulnerability? Here’s How to Report It (with R-Disclosure)
Learn how to report and use this time-saving tool.

By RivuDon
4 min read
📩 Read for Free CLICK HERE.
Hi, I'm Rivek Raj Tamang (RivuDon), a Security Researcher, Bug Hunter, and Ethical Hacker with a Master's in Cybersecurity, a Certified Ethical Hacker from Sikkim, India. I have secured numerous companies, received bounties, swags, Hall of Fames mentions, Letter of Appreciation / Recognition, CVEs and more.
Feel free to connect with me! You can find out more about me on my LinkedIn, I am active there.
Have you ever found a security vulnerability in the wild? Wondering where and how to responsibly disclose a vulnerability without getting into trouble and possibly even earn a reward?
"You found the bug. The adrenaline kicks in. Then you open a new tab and stare blankly, where do I even send this?"
This is the most underrated problem in bug hunting. Most beginners focus 100% on finding bugs and zero percent on reporting them correctly. A bug reported to the wrong place is a bug that never gets fixed and a hunter who never gets credit…
Hi, readers! In this short write-up, I'll explain where and how to report security vulnerabilities responsibly and introduce my tool, R-Disclosure, to make the process easier. Learn how to responsibly disclose vulnerabilities and possibly earn a reward in the process.
What is Responsible Disclosure?
Imagine you're new to bug hunting and discover a vulnerability on a random website. Naturally, you want to report it to the organization.
Should you post the vulnerability on LinkedIn, X, or another social media platform and tag the company asking for a reward?
The answer is a big NO!
Always remember that regardless of the severity, any security vulnerability should be disclosed responsibly through the proper channels. For example, report it to their security@domain.com email address or encrypt your message using their preferred PGP (Pretty Good Privacy) key if requested.
Where Should You Actually Report a Bug?
Some of the most common ways to report include: -
- Security.txt, located at domain.com/.well-known/security.txt or domain.com/security.txt, usually contains email id and a pgp key, most professional companies have this, and is a gold standard.
- Bug Bounty Platforms like HackerOne, Bugcrowd, Intigriti YesWeHack, Synack etc. Simply search for the company or domain name on these platforms to see whether they have an active program.
- VDP, RDP, Bug Bounty policy page some of the companies have a dedicated page for their security reporting some of the directories include /security, /responsible-disclosure, /bug-bounty, /vulnerability-disclosure etc.
- Security Email security@domain.com is the most common go to email for your security needs however some companies do use bugbounty@, psirt@, abuse@, disclosure@, etc as well.
- Social / Linkedin the last part here is kind of a last resort where you need to find the CISO, Security Engineer or IT Team of the company and ask them where you can disclose your bug report.
All of the above methods work well, but searching for them manually can be time-consuming. So why not use a tool where you simply enter a domain name and instantly discover its responsible disclosure resources?
Introducing "R-disclosure "- Your solution
Every time I found a vulnerability in the wild, I got tired of manually searching for the correct reporting channel. So, I built this simple, fast and effective tool. I use it almost every day, and now I'm sharing it with you as well.
Link: https://www.hackracademy.com/r-disclosure.html
- How to use it: simply enter the domain name you want to find for example "nasa.gov" or "nasa" or "reddit" and click on generate links.
- It generates all the relevant search links for you, along with bonus searches on platforms like FireBounty, OpenBugBounty, and Disclose.io.
Tip: Hold the Ctrl key while clicking the generated links to open them in new tabs.
Example of Search Results for Nasa and Reddit.
Using this same approach, I once received a bug bounty from an organization that didn't have a public Bug Bounty Program, VDP, or RDP. By finding the correct security email address, communicating professionally, and responsibly disclosing the vulnerability, I was ultimately rewarded.
Tip: Always follow a top-to-bottom approach during responsible disclosure. Start by using the tool, and if you don't find the information you need, switch to a manual search. The goal is always responsible disclosure, you never know, you might even get rewarded. Happy Hacking! ✨
P.S. If you'd like to contribute, add new features, or have ideas to improve the tool, feel free to let me know!
The End
If you find this article helpful, please do follow, claps and leave a comment to read more from me and encourage me to write more. ♥️
🎯Read my other Bug Bounty Writeups here ⬇️
Rivek's Blog List Edit description
Feel Free to connect with me on LinkedIn: (P.S. Do drop a message when sending a connection request.) https://www.linkedin.com/in/rivektamang/
🧑🏻💻Interested to start Bug Bounty / Ethical Hacking and Cybersecurity
Book a 1:1 mentor session with me: ➡️ RivuDon — Rivek Raj Tamang