Auto VDP
Generate your vulnerability disclosure policy in one click.
A vulnerability disclosure policy is mandatory to comply with regulations, including the EU Cyber Resilience Act, the UK PSTI and the US Cyber Trust Mark.
Generate
Your VDP in one click
Enter your company name and the address that receives vulnerability reports. Auto VDP generates a vulnerability disclosure policy you can copy into your website. Adjust the timelines if ours do not suit you.
Analyse
How good is your VDP?
Enter the address of a brand website or of a vulnerability disclosure policy. Auto VDP looks for the policy the way a security researcher would, scores how easy it is to find against the cetome VDP methodology, and checks that the mandatory information is there.
Licence and price
Free, or without the disclaimer
The free version of Auto VDP contains the disclaimer "Generated with cetome Auto VDP". You must not remove nor change this text: to do so, acquire a licence. The advanced licence also generates a reporting webform and a security.txt. We recommend a premium licence for organisations with several brands.
Privacy
What we record
Auto VDP records the websites you analyse and their results, the details you enter to generate a policy, and the address you give us to receive a report, with your IP address and browser. We never sell or share it, it is deleted after 12 months, and ask us and we delete it sooner. The analysis is performed by AI, which only ever receives the public text of the analysed website. No cookies are set. Read our privacy policy for the details and your rights.
Work together