# Responsible Disclosure

The practice of privately reporting a security vulnerability to the affected organization before it's made public.

**Responsible disclosure[↗](/responsible-disclosure)** is the practice of privately reporting a discovered security vulnerability[↗](/vulnerability) to the affected organization, giving them time to fix it before any public disclosure, rather than releasing the details immediately or exploiting the flaw.

This approach balances the security researcher's contribution with the organization's need to protect users, typically following an agreed timeline before publication. Many companies formalize this through bug bounty[↗](/bug-bounty) programs that reward researchers for responsibly reported findings.
