Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
policymaker — A free, open-source, multi-lingual, template-based VDP policy, safe harbor clause, securitytxt, and DNS Security TXT generator. | Kitploit
Tools/GitHubGitHub/disclose/policymaker
Vulnerability AnalysisWeb SecurityLearning & EducationCurated ResourcesDNS Analysis
GitHubdisclose/policymaker

policymaker

A free, open-source, multi-lingual, template-based VDP policy, safe harbor clause, securitytxt, and DNS Security TXT generator.

View Repository
169111 month agoNot yet reviewed
Website

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
policymaker — generate a real disclosure policy, no lawyer required

policymaker

Generate a real vulnerability-disclosure policy — VDP, safe harbor, security.txt & DNS Security TXT — in minutes. No lawyer required.

Build and Deploy Try it live Powered by dioterms CC0 1.0 Languages PRs welcome

Part of the disclose.io Project — the open, vendor-neutral infrastructure for vulnerability disclosure. Browse the ecosystem →


policymaker.disclose.io is a free, open-source generator that turns a few plain questions about your organization into a complete, defensible security-disclosure setup:

  • a full Vulnerability Disclosure Policy (VDP), with or without a coordinated-disclosure window,
  • a standalone safe-harbor clause to attach to an existing policy,
  • a security.txt file (RFC 9116), and
  • a DNS Security TXT record.

Answer a short wizard, tune the settings, and download — no account, no lawyer, no starting from a blank page. Everything it produces is CC0 1.0: public domain.

Powered by the canonical disclose.io language

policymaker doesn't invent policy text — it ingests the canonical language from dioterms, the disclose.io Framework's single source of truth for disclosure terms. dioterms is vendored as a pinned submodule (vendor/dioterms) and synced into the app at build (scripts/sync-templates.mjs), so every policy policymaker generates descends from the same lawyer-reviewed source — and the language changes only through reviewed, public pull requests upstream. Canonical and deployed never drift.

To adopt newer language: bump the vendor/dioterms submodule pin and re-run the sync. Never hand-edit static/templates/disclose-io-* — dioterms is authoritative.

Getting started

policymaker is a Nuxt.js frontend application.

# 1. clone (with the dioterms submodule)
git clone --recurse-submodules https://github.com/disclose/policymaker.git
cd policymaker

# 2. install dependencies
npm install --legacy-peer-deps

# 3. sync the canonical templates from dioterms
node scripts/sync-templates.mjs

# 4. start the local dev server
npx nuxt dev

Then open http://localhost:3000 and start building.

Already cloned without submodules? Run git submodule update --init first.

Contributing

  • Policy / term wording is not edited here — it lives in dioterms. Open a Discussion/PR there; policymaker picks it up on its next submodule bump.
  • The app itself (UI, flows, generators) — fork → change → PR. Please run npm run lint first.
  • Translations — add the locale to dioterms (terms/languages.json + the term files); policymaker serves whatever dioterms provides.

Suggestions & feedback

Have an idea for the app? Raise an issue. Not comfortable with GitHub? Comment on the disclose.io Community Forum.

Download Tool