---
title: "Netlify’s commitment to security transparency | Netlify Blog"
description: "Netlify is committed to the transparent, responsible disclosure of vulnerabilities for the safety and security of our customers’ data."
source: "https://www.netlify.com/blog/our-commitment-to-security-transparency/"
last_updated: "2026-08-29T12:03:33.000Z"
---
Vulnerabilities happen. The question is how you respond when they do. At Netlify we are committed to the safety and security of our customers’ data. As a part of that commitment we are passionate about being transparent when it comes to the responsible disclosure of vulnerabilities in the packages that our community uses to build a better web. As a part of our community you can rest assured that we will not only fix vulnerabilities in a timely manner but we will disclose what happened so that we not only improve but our community improves as well.

## Netlify’s commitment to responsible disclosure

The responsible disclosure of vulnerabilities is a key tenant of the Netlify Security Team. In each and every case we will only disclose vulnerabilities that have been fully remediated.

## Netlify’s collaboration with bug bounty researchers

We’re passionate about working with our bug bounty research partners to make the Netlify platform better for everyone. Should a researcher come to us with a vulnerability and we are able to extend what they have found, then we will pay out at the extension amount. If you’re an amazing bug bounty researcher, we want to work with you. Have a look at our [public bug bounty program](https://hackerone.com/netlify/) today.

## What can Netlify customers and the community expect going forward?

If we see something, and it constitutes a Critical or High CVE rating, then you can expect that we will responsibly say something about it. Our goal is that we make our community of amazing developers better through transparent disclosures so that we can make the web a safer place together.

## 48 hour notification policy

Should there be a vulnerability where we do need our customers to take action, you can expect that once we’ve completed our investigation you will be contacted within 48 hours, which is the same as our security incident notification policy. Our goal with this process is two-fold: 1) we’ve verified that our customers and community are no longer vulnerable; 2) we’ve verified that customer(s) and the community were not exploited during the exposure window.

## Responsible disclosure of findings to Netlify

You can help us make the web not only a better place but a safer place as well by responsibly reporting your vulnerability findings through our [public bug bounty program](https://hackerone.com/netlify/).

### Share

-   [X (fka Twitter)](https://twitter.com/intent/tweet?text=Netlify’s commitment to security transparency&url=https://www.netlify.com/blog/our-commitment-to-security-transparency/)
-   [LinkedIn](https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fwww.netlify.com%2Fblog%2Four-commitment-to-security-transparency%2F)
-   [Facebook](https://www.facebook.com/sharer.php?u=https://www.netlify.com/blog/our-commitment-to-security-transparency/)
-   [Bluesky](https://bsky.app/intent/compose?text=Netlify’s commitment to security transparency+https://www.netlify.com/blog/our-commitment-to-security-transparency/)

* * *

### Tags

-   [Security](/blog/tags/security/)

## Keep reading

![](/_astro/39409700c858c295fc5c37de304f679e44e21c32-2400x1350_Z1i5x2x.webp)

Opinions & Insights August 14, 2026

[

### The full power of Git, without the friction: A conversation with Netlify CTO Dana Lawson

](/blog/netlify-source-with-netlify-cto-dana-lawson)

-   ![Profile picture of Dana Lawson](/_astro/856bf146d0c05c9dc25d45b59f7eac955fbbd644-512x512_1n84rs.webp)
    
    Dana Lawson
    

![](/_astro/61190f2745496c269dd071680edec773a29eaef7-1800x1013_Z1NFVab.webp)

Opinions & Insights August 12, 2026

[

### Choosing an AI model: one prompt, 11 models, very different results

](/blog/one-prompt-11-models-very-different-results)

-   ![Profile picture of Elad Rosenheim](/_astro/be563e8998105c7e95b4db9110fa16b47cb68acd-230x230_Z2hYOHp.webp)
    
    Elad Rosenheim
    

## Recent posts

News & Announcements August 25, 2026

[

### Compete in OpenAI’s WebMCP Challenge with Netlify

](/blog/compete-openai-webmcp-challenge)

-   ![Profile picture of Karthik Puvvada](/_astro/e5524d3c315ad5114e1d5300d8991bfe902916fe-192x192_Z1w18MB.webp)
    
    Karthik Puvvada
    

News & Announcements August 19, 2026

[

### New clarifying questions in Agent Runners

](/blog/new-clarifying-questions-in-agent-runners)

-   ![Profile picture of Taylor Barnett-Torabi](/_astro/cf4624da8c1286738397b6fecb53bad504df140b-400x400_ZsvK0s.webp)
    
    Taylor Barnett-Torabi
    

Opinions & Insights August 14, 2026

[

### The full power of Git, without the friction: A conversation with Netlify CTO Dana Lawson

](/blog/netlify-source-with-netlify-cto-dana-lawson)

-   ![Profile picture of Dana Lawson](/_astro/856bf146d0c05c9dc25d45b59f7eac955fbbd644-512x512_1n84rs.webp)
    
    Dana Lawson
    

![](/_astro/3f255b372fa958df35802666ee33b4609b2d71bd-1200x1586_1VtE2D.webp)

### How do the best dev and marketing teams work together?

[Access the report](https://www.netlify.com/reports/2024-leadership-trend-report/access/)