# Response times and the disclosure window

**Category:** [Bug Bounty](https://help.totalctrl.app/hc/totalctrl/totalctrl-help-center/en-US/categories/bug-bounty)
**Updated:** 2026-10-04

## Commitments become clocks

On **Policy** you set three numbers, and all three are published:

- **Acknowledge within** — how long before a person replies.
- **Assess within** — how long before you say whether you reproduced it.
- **Disclosure window** — after this, the reporter may publish.

Every report is measured against them. A report past a promised time is badged in the queue and counted on the program overview. A commitment nobody measures is one you will miss in public.
## Only open reports can be late

A closed report is never overdue, and acknowledging a report stops that clock even if the work continues. A control that nags about finished work is one people learn to ignore.
## Promise what you can keep

Three business days is a common commitment and a demanding one. A slower promise you meet is worth more than a fast one you miss, and you can change these numbers at any time.

---

## Related Articles

- [Put the program on your own domain](https://help.totalctrl.app/en-US/articles/bugbounty-custom-domain-1)
- [Scope groups and reward tables](https://help.totalctrl.app/en-US/articles/bugbounty-scope-and-rewards-1)
- [Automate on reports: webhooks and the API](https://help.totalctrl.app/en-US/articles/bugbounty-api-and-webhooks-1)
- [Send reports to Issue Tracking or Jira](https://help.totalctrl.app/en-US/articles/bugbounty-trackers-1)
- [Getting started with Bug Bounty](https://help.totalctrl.app/en-US/articles/bugbounty-getting-started-1)

---
[← Back to TotalCtrl Help Center](https://help.totalctrl.app/en-US/)