
A free, open-source, multi-lingual, template-based VDP policy, safe harbor clause, securitytxt, and DNS Security TXT generator.
Part of the disclose.io Project — the open, vendor-neutral infrastructure for vulnerability disclosure. Browse the ecosystem →
policymaker.disclose.io is a free, open-source generator that turns a few plain questions about your organization into a complete, defensible security-disclosure setup:
security.txt file (RFC 9116), andAnswer a short wizard, tune the settings, and download — no account, no lawyer, no starting from a blank page. Everything it produces is CC0 1.0: public domain.
policymaker doesn't invent policy text — it ingests the canonical language from dioterms, the disclose.io Framework's single source of truth for disclosure terms. dioterms is vendored as a pinned submodule (vendor/dioterms) and synced into the app at build (scripts/sync-templates.mjs), so every policy policymaker generates descends from the same lawyer-reviewed source — and the language changes only through reviewed, public pull requests upstream. Canonical and deployed never drift.
To adopt newer language: bump the
vendor/diotermssubmodule pin and re-run the sync. Never hand-editstatic/templates/disclose-io-*— dioterms is authoritative.
policymaker is a Nuxt.js frontend application.
# 1. clone (with the dioterms submodule)
git clone --recurse-submodules https://github.com/disclose/policymaker.git
cd policymaker
# 2. install dependencies
npm install --legacy-peer-deps
# 3. sync the canonical templates from dioterms
node scripts/sync-templates.mjs
# 4. start the local dev server
npx nuxt dev
Then open http://localhost:3000 and start building.
Already cloned without submodules? Run
git submodule update --initfirst.
npm run lint first.terms/languages.json + the term files); policymaker serves whatever dioterms provides.Have an idea for the app? Raise an issue. Not comfortable with GitHub? Comment on the disclose.io Community Forum.