disclose.io · state of disclosure

The world's biggest companies, graded on vulnerability disclosure

L0 Not PresentL1 Contact OnlyL2 Basic VDPL3 Partial Safe HarborL4 Full Safe HarborL5 Full Safe Harbor + CVD

🇺🇸 United States · snapshot 2026-06-21 · 100 companies · graded against the disclose.io Maturity Model

72
have a verifiable way to report a bug
60
publish a real VDP (Level 2+)
34
offer safe harbor (Level 3+)
9
full safe harbor — safe to test (Level 4+)
0
reach Level 5 — safe harbor + disclosure deadline

Level 4 — Full Safe Harbor (9)

L4 Meta PlatformsL4 General MotorsL4 ComcastL4 TeslaL4 BoeingL4 Procter & GambleL4 CaterpillarL4 Prudential FinancialL4 TIAA
#CompanyReportPolicyDisclose.io Maturity LevelLast verified
1Amazon
amazon.com
Web form ↗policy ↗ L12026-06-21
2Walmart
walmart.com
Web form ↗policy ↗ L32026-06-21
3UnitedHealth Group
unitedhealthgroup.com
Web form ↗policy ↗ L22026-06-21
4Apple
apple.com
Web form ↗policy ↗ L22026-06-21
5Alphabet
google.com
Web form ↗policy ↗ L22026-06-21
6CVS Health
cvshealth.com
Web form ↗policy ↗ L22026-06-21
7Berkshire Hathaway
berkshirehathaway.com
L02026-06-21
8McKesson
mckesson.com
Web form ↗policy ↗ L22026-06-21
9Exxon Mobil
exxonmobil.com
L02026-06-21
10Cencora
cencora.com
L02026-06-21
11Microsoft
microsoft.com
Web form ↗policy ↗ L22026-06-21
12JPMorgan Chase
jpmorganchase.com
Web form ↗policy ↗ L22026-06-21
13Costco Wholesale
costco.com
HackerOne ↗policy ↗ L32026-06-21
14Cigna Group
cigna.com
Email ↗policy ↗ L32026-06-21
15Cardinal Health
cardinalhealth.com
Email ↗policy ↗ L22026-06-21
16Nvidia
nvidia.com
Web form ↗policy ↗ L22026-06-21
17Meta Platforms
meta.com
Web form ↗policy ↗ L42026-06-21
18Elevance Health
elevancehealth.com
L02026-06-21
19Centene
centene.com
HackerOne ↗policy ↗ L32026-06-21
20Bank of America
bankofamerica.com
PSIRT ↗ L02026-06-21
21Chevron
chevron.com
L02026-06-21
22Ford Motor
ford.com
HackerOne ↗policy ↗ L32026-06-21
23General Motors
gm.com
HackerOne ↗policy ↗ L42026-06-21
24Citigroup
citi.com
Bugcrowd ↗policy ↗ L22026-06-21
25Home Depot
homedepot.com
L02026-06-21
26Fannie Mae
fanniemae.com
Web form ↗policy ↗ L22026-06-21
27Kroger
kroger.com
Bugcrowd ↗policy ↗ L32026-06-21
28Verizon
verizon.com
Email ↗policy ↗ L22026-06-21
29Phillips 66
phillips66.com
HackerOne ↗policy ↗ L02026-06-21
30Marathon Petroleum
marathonpetroleum.com
L02026-06-21
31StoneX Group
stonex.com
security.txt ↗ L12026-06-21
32State Farm
statefarm.com
Web form ↗policy ↗ L32026-06-21
33Freddie Mac
freddiemac.com
Bugcrowd ↗policy ↗ L22026-06-21
34Humana
humana.com
security.txt ↗ L12026-06-21
35AT&T
att.com
HackerOne ↗policy ↗ L22026-06-21
36Goldman Sachs
goldmansachs.com
HackerOne ↗policy ↗ L22026-06-21
37Comcast
xfinity.com
Bugcrowd ↗policy ↗ L42026-06-21
38Wells Fargo
wellsfargo.com
Email ↗policy ↗ L32026-06-21
39Morgan Stanley
morganstanley.com
Web form ↗policy ↗ L22026-06-21
40Valero Energy
valero.com
L02026-06-21
41Dell Technologies
dell.com
Web form ↗policy ↗ L12026-06-21
42Target
target.com
HackerOne ↗policy ↗ L32026-06-21
43Tesla
tesla.com
Bugcrowd ↗policy ↗ L42026-06-21
44Walt Disney
disney.com
HackerOne ↗policy ↗ L32026-06-21
45Johnson & Johnson
jnj.com
Email ↗policy ↗ L22026-06-21
46PepsiCo
pepsico.com
HackerOne ↗policy ↗ L22026-06-21
47Boeing
boeing.com
Web form ↗policy ↗ L42026-06-21
48UPS
ups.com
HackerOne ↗policy ↗ L32026-06-21
49RTX
rtx.com
Web form ↗policy ↗ L22026-06-21
50FedEx
fedex.com
Web form ↗policy ↗ L32026-06-21
51Progressive
progressive.com
L02026-06-21
52Lowe's
lowes.com
HackerOne ↗policy ↗ L32026-06-21
53Energy Transfer
energytransfer.com
L02026-06-21
54Procter & Gamble
pg.com
Web form ↗policy ↗ L42026-06-21
55Sysco
sysco.com
L02026-06-21
56American Express
americanexpress.com
security.txt ↗ L02026-06-21
57Albertsons
albertsons.com
Web form ↗policy ↗ L32026-06-21
58Archer Daniels Midland
adm.com
L02026-06-21
59MetLife
metlife.com
L02026-06-21
60HCA Healthcare
hcahealthcare.com
Web form ↗policy ↗ L22026-06-21
61Lockheed Martin
lockheedmartin.com
Web form ↗policy ↗ L32026-06-21
62New York Life
newyorklife.com
L02026-06-21
63Capital One
capitalone.com
Web form ↗policy ↗ L32026-06-21
64Allstate
allstate.com
Email ↗policy ↗ L12026-06-21
65Caterpillar
caterpillar.com
HackerOne ↗policy ↗ L42026-06-21
66IBM
ibm.com
Web form ↗policy ↗ L12026-06-21
67Eli Lilly
lilly.com
Web form ↗policy ↗ L32026-06-21
68Merck
merck.com
HackerOne ↗policy ↗ L32026-06-21
69Nationwide
nationwide.com
Web form ↗policy ↗ L22026-06-21
70Broadcom
broadcom.com
PSIRT ↗policy ↗ L22026-06-21
71Delta Air Lines
delta.com
Email ↗policy ↗ L12026-06-21
72Publix Super Markets
publix.com
Email ↗ L02026-06-21
73Pfizer
pfizer.com
HackerOne ↗policy ↗ L32026-06-21
74TD Synnex
tdsynnex.com
L02026-06-21
75ConocoPhillips
conocophillips.com
L02026-06-21
76Galaxy Digital
galaxy.com
security.txt ↗ L12026-06-21
77AbbVie
abbvie.com
Web form ↗policy ↗ L12026-06-21
78Prudential Financial
prudential.com
HackerOne ↗policy ↗ L42026-06-21
79TJX
tjx.com
security.txt ↗ L12026-06-21
80Performance Food
pfgc.com
L02026-06-21
81United Airlines
united.com
Bugcrowd ↗policy ↗ L32026-06-21
82Oracle
oracle.com
Email ↗policy ↗ L12026-06-21
83Cisco Systems
cisco.com
Web form ↗policy ↗ L22026-06-21
84HP
hp.com
PSIRT ↗policy ↗ L22026-06-21
85Charter Communications
corporate.charter.com
L02026-06-21
86American Airlines
aa.com
HackerOne ↗policy ↗ L32026-06-21
87Tyson Foods
tysonfoods.com
L02026-06-21
88Intel
intel.com
PSIRT ↗policy ↗ L32026-06-21
89Enterprise Products
enterpriseproducts.com
L02026-06-21
90Ingram Micro
ingrammicro.com
L02026-06-21
91General Dynamics
gd.com
L02026-06-21
92Uber Technologies
uber.com
HackerOne ↗policy ↗ L32026-06-21
93USAA
usaa.com
Web form ↗policy ↗ L12026-06-21
94TIAA
tiaa.org
HackerOne ↗policy ↗ L42026-06-21
95Liberty Mutual Insurance
libertymutualgroup.com
L02026-06-21
96Travelers
travelers.com
Web form ↗policy ↗ L32026-06-21
97Bristol-Myers Squibb
bms.com
L02026-06-21
98Coca-Cola
coca-cola.com
Web form ↗policy ↗ L32026-06-21
99Nike
about.nike.com
Web form ↗policy ↗ L22026-06-21
100Massachusetts Mutual
massmutual.com
Email ↗policy ↗ L22026-06-21