Never lose a vulnerability
report again
The dead-simple drop-in replacement for security@domain.com. A proper dashboard, structured reports, severity ratings, and real-time status tracking. All in one link.
The dead-simple drop-in replacement for security@domain.com. A proper dashboard, structured reports, severity ratings, and real-time status tracking. All in one link.
Features
A purpose-built platform for receiving, tracking, and managing vulnerability reports. No more lost emails, no more spreadsheets.
Create a project, get a unique reporting URL. Share it in your README, security.txt, or anywhere. That's it.
See every report as it comes in. Severity ratings, statuses, response tracking — no more digging through email threads.
Sort by severity, status, reporter, or date. Full-text search across all reports. Find anything in seconds.
Every report gets a proper CVSS-style severity rating. Critical, high, medium, low — at a glance.
Instant notifications when new reports come in. Track which ones need your response. Zero reports lost.
Reporters can sign up with GitHub or email. You know exactly who's reporting. Block bad actors instantly.
How it works
No complex setup. No procurement process. No sales calls. Just create, share, and start receiving properly structured vulnerability reports.
Link a GitHub repo or name a project. Takes 30 seconds. We generate a unique reporting URL for you.
https://zeroday.report/r/your-projectDrop it in your security.txt, README, or wherever you currently point people to security@. Done.
# security.txt
Contact: https://zeroday.report/r/your-projectReports come in structured with severity, details, and reproduction steps. Triage, respond, and resolve — all from one dashboard.
$ 3 new reports → 1 critical, 1 high, 1 mediumComparison
We're not competing with HackerOne. We're replacing the inbox you're already ignoring.
Pricing
Scale from individual vulnerability intake to enterprise-grade incident response. No hidden fees.
Solo devs / OSS maintainers
Essential vulnerability intake for individual developers.
Small teams / startups
Full team collaboration with reporter communication.
Agencies / growing SaaS
AI-powered incident response for critical vulnerabilities.
| Features | Free | Plus | Pro |
|---|---|---|---|
| Email notifications | |||
| Basic dashboard | |||
| GitHub authentication | |||
| Live chat with reporters | |||
| Internal report notes | |||
| AI phone calls (Critical reports) |
Get started with ZeroDay.report and replace security@domain.com with something that actually works.
Free for open source. Always. Just ask.