Skip to content
Suraksha VDP · Discover & disclose

Findings need somewhere legitimate to go.

Planned

A researcher who finds a real flaw in an Indian company often has no clear, safe way to report it. So it goes unreported, or it goes public. Suraksha VDP is being built to be the third option.

Suraksha VDP is Shadow Security's responsible vulnerability disclosure platform, connecting security researchers with organisations.

The problem

Right now, doing the right thing is the hard path.

Someone finds a flaw in a service used by thousands of people. They look for a security contact, find a generic support address, send an email, and nothing happens. Or worse, they get treated as a threat.

So the finding sits there unfixed, or it surfaces publicly with users still exposed. Both outcomes are worse than the one everybody wanted.

The missing piece is not goodwill. It is a defined channel for vulnerability reporting, a shared process, and a record that protects both sides.

The lifecycle

From discovery to credit.

Six stages, with a clear owner at each one. The point is that nothing falls into a gap between the researcher and the organisation.

The disclosure lifecycle has six stages: discover and report, done by the researcher; triage and fix, done by the organisation; verify, done by both; and recognise, done by the organisation.

  1. Researcher

    Discover

    A researcher finds something real.

  2. Researcher

    Report

    It goes to a defined channel, not a public thread.

  3. Organisation

    Triage

    The report is assessed, deduplicated and prioritised.

  4. Organisation

    Fix

    The issue is remediated with the finding on record.

  5. Both

    Verify

    The researcher confirms the fix holds.

  6. Organisation

    Recognise

    Credit is given, and the work becomes reputation.

Two sides

Built for both ends of the report.

For researchers

A channel that respects the work

  • A defined place to send a finding, instead of guessing at an address
  • Visibility into what happened to your report
  • Credit for legitimate findings, on the record
  • A profile that accumulates into something you can point at
For organisations

A process instead of a panic

  • Reports arriving in a structured form rather than scattered emails
  • Triage, deduplication and prioritisation in one place
  • A remediation trail you can show an auditor or a customer
  • A way to treat researchers as allies rather than incidents

Intended capabilities while Suraksha VDP is in development. Nothing on this page is available yet.

Boundaries

What this is not.

Not a hacker marketplace
Suraksha VDP does not broker offensive work or sell access to anything.
Not authorisation to test anything
Being a member of a disclosure platform is not permission to probe systems. Testing requires the owner's authorisation, and that will not change.
Not a shield
Responsible disclosure protects users and researchers acting in good faith. It is not cover for activity that was not in good faith.
Questions

About Suraksha VDP.

What is Suraksha VDP?
Suraksha VDP is Shadow Security’s responsible vulnerability disclosure platform, connecting security researchers with organisations. Researchers report findings through a defined channel; organisations receive, triage, remediate, verify and credit them.
What is responsible vulnerability disclosure?
It is the practice of reporting a security flaw privately to the organisation that can fix it, giving them a reasonable opportunity to remediate before any public discussion. It protects the users of the system while still ensuring the problem gets addressed.
Is this a bug bounty marketplace?
No. Suraksha VDP is disclosure infrastructure, not a marketplace for offensive work. There is no brokering of access, no hacking-as-a-service, and no testing of systems without the owner’s authorisation.
Who can participate as a researcher?
The intention is that anyone doing legitimate security research can participate. Details of onboarding will be published before launch. Suraksha VDP is planned and not yet open.
Why is Suraksha VDP coming after Suraksha Labs?
Because a disclosure platform without researchers is an empty inbox. Suraksha Labs builds the community of people capable of finding real issues; Suraksha VDP gives that community somewhere for their findings to go. Building them in the other order would produce infrastructure with nobody to use it.
How will AI be used?
Planned assistance covers summarising reports, spotting probable duplicates, and helping draft communication back to researchers. Severity and validity judgements are intended to stay with people, because those decisions carry consequences that should not be automated away.