Seventeen plain-English questions across governance, technical, and communication readiness — and a scored snapshot of how prepared you are to receive and handle vulnerability reports before the first one arrives. About ten minutes. No email required.
Plain-English product security — without us ever seeing your answers. Everything stays in your browser. Nothing is transmitted or tracked.
Three readiness dimensions. The assessment covers what a Product Security Incident Response Team (PSIRT) needs before the first report arrives: governance (policy, ownership, intake), technical (triage, remediation, advisories), and communication (reporters, customers, regulators).
What you get. An overall score, a breakdown by dimension, and plain-English next steps — drawn from the FIRST PSIRT Services Framework and widely recognised practice.
What it isn't. This is general guidance, not a professional audit and not legal advice. Every recommendation is optional; following it reduces common risks but does not guarantee any outcome. Responsibility for your programme remains with you.
Version 1 · Updated 2026-07-21
For a team that ships software and wants to be ready to receive and act on a vulnerability report.
When you have worked through this, you will have: your free readiness result, and a disclosure policy you can adapt and publish. Download this as a PDF.
When you outgrow the free tier, the Solo toolkit turns the policy into a working PSIRT — a report intake, a triage runbook, and advisory drafting — with a Start here catalog to sequence them. See the Solo, Team and Enterprise editions →
Everything behind this free assessment — the working documents, templates, runbooks, and depth to put it into practice. Three editions to fit how you work.
See the full toolkit & pricing →One-time purchase · files you own forever · 30-day money-back guarantee.