Skip to content
Your cart

Your cart is empty. Let's fix that!

Search

Responsible Disclosure: Report Vulnerabilities

Harbor's Responsible Disclosure page invites security researchers, partners, and customers to report potential vulnerabilities affecting Harbor's digital assets. The page outlines Harbor's commitment to trust, respect, transparency, and the common good in handling disclosures, and provides clear guidelines for submitting vulnerability reports. Through this submission form, researchers can share technical details, proof-of-concept materials, and other relevant information, helping Harbor maintain the safety and integrity of its products and services.

Harbor Vulnerability Disclosure Policy

Our Philosophy

At Harbor, responsible vulnerability disclosure is built on trust, respect, transparency, and a shared commitment to the common good.

We believe security is a collaborative effort. By working together with the security community, we strengthen the protection, privacy, and reliability of Harbor’s platform and the people who depend on it.

Who Can Report

Harbor welcomes vulnerability reports from:

  • Independent security researchers
  • Customers and users
  • Industry partners and vendors
  • Consultants and security professionals

A security vulnerability is defined as any unintended weakness that could compromise the confidentiality, integrity, or availability of Harbor systems, products, or data.

Scope

This policy applies to all digital assets owned, operated, or maintained by Harbor, including:

  • Public-facing websites
  • Applications and services
  • Supporting infrastructure

Our Commitment to Researchers

Trust: We handle all interactions with researchers professionally and protect the confidentiality of your submissions.

Respect: We value your work and recognize your role in helping keep our users safe.

Transparency: We communicate openly throughout the validation and remediation process.

Common Good: We prioritize actions that protect users and minimize risk to the broader community.

What We Ask of Researchers

Trust: Please report vulnerabilities responsibly and allow us reasonable time to investigate and resolve issues before public disclosure.

Respect: Avoid actions that could:

  • Violate user privacy
  • Disrupt services
  • Degrade user experience
  • Damage or destroy data

Transparency: Provide clear, detailed information so our team can reproduce and validate the issue quickly.

Common Good: Do not publicly disclose vulnerabilities until they have been verified and addressed by Harbor.

How to Report a Vulnerability

If you discover a potential vulnerability in any Harbor system or asset, please submit it through our official reporting channel.

Our security team will:

  1. Acknowledge receipt of your report
  2. Investigate and validate the issue
  3. Take appropriate steps to remediate
  4. Keep you informed throughout the process

Submission Form

The Vulnerability Rating Taxonomy is the baseline guide used for classifying technical severity.