Provision record
X · X Terms of Service · View original document ↗

Security Researchers Must Follow Vulnerability Reporting Program

Medium severity Explicit document language Common · 282 of 352 platforms
Stay ahead of the changes
Track X and get the diff the day its terms change.
Share 𝕏 Share in Share 🔒 PDF

This analysis describes what X's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

Clause Stability Stable

0
Changes
5
Months Monitored
Jul 10, 2026
First Seen
Jul 10, 2026
Last Seen
This clause type exists across 4244 other provisions on other platforms.

How other platforms handle this

Segment Medium

You will comply with the applicable Partner Program guides and policies available at https://www.twilio.com/legal/partner-program-policies

Perplexity AI Medium

You agree that Promotional Codes: (a) must be used in a lawful manner; (b) must be used for the intended audience and purpose; (c) may not be duplicated, sold or transferred in any manner...

Mailchimp Medium

You may only use Mailchimp in accordance with these best practices, and we may suspend or terminate your account if you violate them.

See all platforms with this clause type →
▸ View Original Clause Language DOCUMENT RECORD
"
If you are a security researcher, you are required to comply with the rules of our Vulnerability Reporting Program.

Excerpt from X's Terms of Service

Applicable regulations

CFAA
United States Federal
DMCA
United States Federal
DSA
European Union

Provision details

Document information
Document
X Terms of Service
Entity
X
Document last updated
May 5, 2026
Tracking information
First tracked
May 7, 2026
Last verified
Aug. 5, 2026
Record ID
CA-P-019389
Document ID
CA-D-00029
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
436b3f9c4cdebe0406beb518cf02d7e97323b5f95cd1df78627d8891102b7279
Analysis generated
May 7, 2026 22:56 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: X
Document: X Terms of Service
Record ID: CA-P-019389
Captured: 2026-05-07 22:56:42 UTC
SHA-256: 436b3f9c4cdebe04…
URL: https://conductatlas.com/platform/x/x-terms-of-service/provision/CA-P-019389/security-researchers-must-follow-vulnerability-reporting-program/
Accessed: Aug. 6, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Get the research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.

Frequently Asked Questions

What does X's Security Researchers Must Follow Vulnerability Reporting Program clause do?

The clause states: “If you are a security researcher, you are required to comply with the rules of our Vulnerability Reporting Program.”

How many platforms have this type of clause?

ConductAtlas has identified this type of provision across 282 platforms. See the full comparison.

Is ConductAtlas affiliated with X?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by X.