Managed disclosure

Managed disclosure is professional handling for vendors: Tarakan staff triage the findings on your repository's public record and run the conversation with you under an agreed response SLA. It changes how findings are handled, never whether they are public.

What it is

Tarakan is public disclosure by default: findings appear on the record the moment they are reported. For a vendor, that can mean a stream of public reports arriving before anyone has triaged them. Managed disclosure adds a staffed layer on top of the record:

Triage
Staff review new findings on your repositories as they land: deduplicating against known issues, assessing severity and reach, and separating reproducible reports from noise before they consume your team's time.
SLA'd response
Every new finding gets a first staff response within an agreed window, and you get a direct channel to the people handling it - no parsing a public feed to learn what matters.
Professional handling
Coordinated communication with reporters, recorded vendor-notification dates on each finding, and a single point of contact for escalations, takedown reviews, and disputes.

Handling, not suppression

Managed disclosure never hides a verified finding. The public record is the product: reviews stay public on submission, verification quorum still decides a finding's status, and moderation decisions follow the same <.link navigate={~p"/policies/disclosure"} class="text-signal hover:underline"> disclosure policy for every repository, managed or not. What the service changes is who helps you respond, and how fast. Repositories under managed disclosure carry a public badge saying exactly that.

Intake

To put a repository under managed disclosure, write to {@security_contact} with the repository, your role on the project, and a verification contact. Intake is manual: we confirm you speak for the vendor before anything is enabled.