
Closed
Posted
Paid on delivery
I need a Coordinated Vulnerability Disclosure system built entirely from open-source components and delivered as software only—no appliances or proprietary add-ons. The core feature I must have is a robust workflow for tracking and managing reported vulnerabilities, from initial submission through resolution and disclosure. The application has to run smoothly on a Linux server, so please choose libraries and frameworks that are well supported in that environment. For user access, multi-factor authentication is mandatory; I want researchers, internal engineers, and any third-party responders to sign in with something stronger than a simple password. You are free to select or combine existing open-source projects (for example, Bug Bounty platforms, ticketing systems, or secure messaging stacks) as long as the final product offers: • A clean web interface for submitting, updating, and viewing vulnerability tickets • Role-based access so different stakeholders can see only what they need • An audit trail for every action taken on a report • Secure data storage with encryption for sensitive attachments and notes Hand-over items: source code in a public or private repo, a one-command deployment script (Docker or Ansible preferred), and concise documentation that lets me install, configure, and maintain the system myself. I’ll test the build on a fresh Linux VM; acceptance is complete when I can reproduce the install steps and walk through a sample vulnerability report from submission to closure without errors.
Project ID: 40688575
174 proposals
Remote project
Active 3 days ago
Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs
174 freelancers are bidding on average $6,747 USD for this job

Hello, I am Dr. Rajesh Rolen, PhD in Computer Science & Engineering, with experience of over 20+ years in PHP, Web Development, MySQL, Software Architecture, Docker As a preferred freelancer in the top 1%, I have done 400+ projects here on freelancer.com, I have 4.9 ratings out of 5 on average, which showcases my quality of work and timely delivery. Key Highlights: - Free Hosting Support on the Cloud or any desired platform. - Free 3 months of post-delivery support to ensure that our client doesn’t face any challenges after the launch of the project. - Free Dedicated tester on projects to ensure quality delivery, so clients don’t need to act as a tester. - 10+ Years experience UI/UX team to ensure intuitive UI. Portfolio: https://www.freelancer.com/u/Microlent Please open the chat and send me a message, so we can have a more detailed discussion about the project to give you the project timeline and cost. Thank you for considering my services. I look forward to engaging in a productive conversation and understanding how I can be of assistance in bringing your project to life. Regards Rajesh Rolen
$5,000 USD in 90 days
9.5
9.5

Hi, I'm Elias, a Miami-based senior software engineer with 20 years of experience in web development, focusing on secure and efficient systems. I see you need a Coordinated Vulnerability Disclosure (CVD) platform built from open-source components. Your goal is to create a reliable system for effective vulnerability reporting and management. I have experience building similar systems that prioritize secure architecture, user-friendly interfaces, and scalability. My approach would involve the following phases: 1) Understand the business workflow and technical requirements. 2) Design the user experience and architecture. 3) Develop core features and integrations using open-source tools. 4) Conduct thorough testing to ensure reliability. 5) Deploy the solution and provide ongoing support. Could you please clarify the following questions to help me better understand the project? 1) What specific workflows do you envision for reporting and managing vulnerabilities? 2) Are there specific integration requirements with existing systems? 3) How will user roles and permissions be managed within the platform? I've built similar systems before, most of which were completed under NDA, so I can't share them publicly, but I'm happy to discuss the architecture and technical decisions. Additionally, I will ensure the architecture is scalable and maintainable for future enhancements.
$7,500 USD in 26 days
8.7
8.7

I propose a secure and scalable Coordinated Vulnerability Disclosure system tailored to your needs, leveraging open-source components. Key features include a user-friendly web interface, role-based access control, an audit trail, and secure data storage. The hand-over will include source code, deployment scripts, documentation, and testing on a Linux VM. My expertise ensures a scalable, maintainable, and performance-driven solution. Let's partner to create a system that meets your requirements and evolves with your security needs.
$9,000 USD in 5 days
8.8
8.8

Hi, I noticed you specifically want an open-source CVD system rather than another proprietary vulnerability-management product. Rather than building every component from scratch, I’d first evaluate the right open-source security/ticketing foundation and then build the missing workflow around it — submission, triage, role-based access, MFA, audit trail, encrypted evidence, remediation and disclosure. Quick question: do you already have an open-source project you want to build on, or would you like us to recommend the most suitable foundation? We’ve handled workflow-heavy MVPs and security-sensitive applications, and can package the final system with Docker/Ansible for a clean Linux deployment. Estimated: 6–8 weeks depending on the base platform and customization. If you share your preferred open-source stack (if any), I can suggest the implementation direction. Best, SNR
$5,000 USD in 20 days
9.1
9.1

Dear , We carefully studied the description of your project and we can confirm that we understand your needs and are also interested in your project. Our team has the necessary resources to start your project as soon as possible and complete it in a very short time. We are 25 years in this business and our technical specialists have strong experience in PHP, Linux, Software Architecture, MySQL, Docker, Web Development, Open Source, Ansible and other technologies relevant to your project. Please, review our profile https://www.freelancer.com/u/tangramua where you can find detailed information about our company, our portfolio, and the client's recent reviews. Please contact us via Freelancer Chat to discuss your project in details. Best regards, Sales department Tangram Canada Inc.
$7,247 USD in 5 days
8.9
8.9

Hi, ★★★ PHP / LINUX / DOCKER SPECIALIST ★★★ For your project, I will implement a Coordinated Vulnerability Disclosure system using open-source components. The core workflow will involve tracking vulnerabilities from submission to resolution. I will utilize well-supported libraries and frameworks for Linux to ensure compatibility. I will integrate multi-factor authentication for secure user access, allowing researchers and engineers to log in safely. The web interface will be user-friendly, enabling easy submission and management of vulnerability tickets. Role-based access will be implemented to restrict visibility based on user roles, ensuring confidentiality. To maintain a clear audit trail, I will log every action taken on reports. Sensitive data will be securely stored with encryption. I will provide the source code in a private repository, along with a one-command deployment script using Docker. Documentation will be concise, guiding you through installation and configuration. To get started, I will need access to your Linux server environment and any specific requirements you have for the user roles. Thanks!
$5,000 USD in 10 days
8.3
8.3

Hi there, I can help you build this CVD platform as a clean, maintainable web system using proven open-source components rather than custom reinvention. The goal, as I understand it, is to give researchers, internal engineers, and third-party responders a secure place to submit reports, track remediation, and close the loop with a complete audit trail. I would keep the stack practical for Linux deployment, likely using PHP or Node.js with MySQL/PostgreSQL, Docker, and a trusted MFA flow. My focus would be on role-based access, encrypted storage for sensitive notes and attachments, and a workflow that is easy to operate, review, and extend without locking you into proprietary tools. I can also deliver a one-command deployment, source in a repo, and concise handover docs so you can reproduce the install on a fresh VM and validate the full report lifecycle with confidence. If helpful, I can suggest the best open-source building blocks for the simplest reliable path forward.
$8,000 USD in 35 days
7.9
7.9

You need more than a ticket system with a security theme — the hard part is making vulnerability intake, triage, coordination, remediation, and disclosure behave like one reliable process. If the architecture is chosen badly, Linux compatibility is easy to achieve but audit trails, scoped visibility, and secure evidence handling become messy later. I’d map the states, roles, and disclosure checkpoints first, then assemble the open-source stack around those rules. I’ve handled builds where the deliverable was not just “working software” but something the client could deploy again on a clean server and maintain independently. That matches your acceptance criteria well: reproducible install, clear documentation, strong authentication, and a sample end-to-end report flow that works without manual patching after deployment. A small but useful extra I’d add is seeded demo data so your acceptance walkthrough is faster. - Do you already have any preference for the core stack, such as Django/Node-based tooling, or should I recommend the best open-source combination for maintainability? - Will researchers be self-registering, or should account creation be controlled by admins only? - Do you need email notifications and disclosure reminders as part of the workflow?
$5,000 USD in 7 days
7.8
7.8

Hi! This is something we can definitely handle Before I put a firm proposal together, the one thing I need to understand is how much of the workflow is already mapped out on your end. Specifically: do you have defined SLA rules for each vulnerability severity, or should we propose a baseline (e.g., 90-day disclosure window, escalation triggers)? That shapes how complex the state machine behind the ticket lifecycle needs to be, and it's the piece that varies most between a straightforward build and a significantly larger one. On how we'd approach it: rather than building from scratch, we'd evaluate proven open-source bases — platforms like VulnReport or a hardened GitLab+Jira-equivalent OSS stack — and extend them to meet your spec: RBAC, MFA, encrypted attachments, and a full audit log. What you'd get is a codebase you actually own and can maintain, not a fork of something unmaintainable. Deployment would be a single Docker Compose or Ansible playbook, tested against a clean Linux VM before handover, exactly as you described for acceptance. Documentation would cover install, configuration, and day-to-day ops — written for someone who won't be calling us afterward. Recurring costs — any third-party MFA provider, hosting, storage — run on your accounts and we'll flag them before anything is finalized. Happy to keep working through the scope details from here. Gustavo & the DoTheCode team
$8,500 USD in 30 days
7.9
7.9

Howdy, A vulnerability disclosure platform is only as strong as the boundaries protecting the reports inside it. Researchers, engineers, and third party responders need to collaborate efficiently, but sensitive findings and attachments must only be visible to the people who are actually authorised to access them. I’d make that security model a foundation of the architecture rather than something added later. I’d build the solution entirely from open source components and keep it Linux friendly, with MFA, role based permissions, immutable audit history, and protected storage for sensitive data. The deployment would also be reproducible on a clean VM, using Docker or Ansible to package the application and its dependencies into a straightforward installation process. I’d structure the architecture around a clear submission to closure workflow so reports can move through triage, investigation, remediation, and closure without stitching together unrelated tools that become difficult to maintain later. I can also provide the complete source repository and concise operational documentation required for handover and acceptance testing, with the deployment process documented clearly for future maintenance. Portfolio link: https://www.freelancer.pk/u/Hammadhassan21 Best regards, Hammad Hassan
$5,000 USD in 21 days
7.6
7.6

Hi, I've built a secure CI pipeline with deterministic ingestion and Docker-based deployment, one-command spin-up on Linux included. Secure CI Pipeline & Deterministic Ingestion, 5 stars, client said we got the app to a great start. On the CVD workflow, the audit trail is the part that decides trust. I'd store every state change as an append-only event log, separate from editable ticket fields, so a report's full history from submission to disclosure can never be silently altered. For encryption I'd keep sensitive attachments and notes encrypted at rest with keys outside the DB. MFA via TOTP fits cleanly with role-based access. One question: do you want researcher self-registration open, or invite-only with internal approval before an account is active? I'd start with a milestone on the deployable skeleton so you release only after it installs clean on your VM. Adil
$6,729.55 USD in 21 days
7.5
7.5

Hi, I’d be interested in building this open-source Coordinated Vulnerability Disclosure (CVD) platform as a secure, self-hosted Linux application. A few questions: Do you already have a preferred open-source foundation, or should I evaluate and select the best fit? Which MFA methods are required—TOTP, WebAuthn/passkeys, or both? Should encrypted attachments use application-level encryption or server-side encrypted storage? I can deliver the complete workflow from vulnerability submission → triage → assignment → remediation → disclosure/closure, including RBAC, MFA, audit logging, encrypted sensitive data/attachments and a clean web interface. I’d use Docker-based deployment with well-supported open-source components and keep the architecture easy for your team to maintain. The final handover will include source code, one-command installation, configuration and maintenance documentation. I’ll also validate the deployment on a fresh Linux VM and test the complete vulnerability lifecycle against your acceptance criteria. Budget: $5,000–$10,000 Availability: Immediate Engagement: Fixed scope Best Regards, Dinesh L
$8,000 USD in 25 days
8.0
8.0

Hello!, This is James from Hollywood... Your CVD platform needs to do one thing very well: make vulnerability reporting, triage, validation, and disclosure feel organized, secure, and easy to operate without locking you into a closed stack. I can build this cleanly with open-source components only, and structure it so the system is maintainable from day one. My approach: 1. Define the workflow clearly: intake, validation, case tracking, response deadlines, and disclosure states. 2. Build the core app in PHP/MySQL with a secure Linux/Docker setup. 3. Add automation with Ansible for deployment and repeatable environments. 4. Harden, audit log, set role permissions, and test for real-world reliability. The real pain point here is not just “building a portal,” but building a workflow that keeps disclosure moving without chaos, missed updates, or security gaps. That’s where I’d focus. I’ve built similar systems for a security-focused reporting portal, an internal incident tracking dashboard, a compliance workflow app, and a private case management tool for a SaaS team. Quick questions: - Do you want this to support public submissions only, or private researcher accounts too? - Should the workflow include SLA timers and auto-reminders? - Any preferred open-source components already in mind, or should I propose the full architecture? If you want, I can map the architecture and delivery phases before coding so we avoid rework.
$7,800 USD in 26 days
7.2
7.2

Hello, CUSTOM OPEN-SOURCE CVD PLATFORM {{{ I HAVE CREATED SIMILAR BEFORE AND I CAN SHOW YOU }}} I understand you need a complete software-only Coordinated Vulnerability Disclosure platform built from open-source components, with no proprietary dependencies or recurring licence fees. I can develop the full CVD lifecycle covering public and anonymous vulnerability reporting, secure attachments, MFA and RBAC, triage, CVSS 3.1/4.0 and CWE classification, TLP controls, multi-stakeholder coordination, deadlines/embargoes, CVE tracking, secure encrypted communication, advisories, reporting, REST API, administration and complete audit trails. The system will support Macedonian/Cyrillic and English, with separate production/test environments and deployment on Linux infrastructure. Security will include encryption at rest/in transit, protected reporter identity, append-only audit records, attack protections, SBOM, reverse proxy/WAF support, configurable retention and GDPR requirements. I will also ensure the solution remains portable, with open-source components, source ownership, documented deployment and data export without vendor lock-in. I have 11+ years of experience in software development, Linux, Docker, secure web applications, APIs, databases, and enterprise systems. I WILL PROVIDE 2 YEAR FREE ONGOING SUPPORT AND COMPLETE SOURCE CODE. I am available according to your convenient time zone and can start immediately. I eagerly await your positive response. Thanks, Christina
$5,000 USD in 30 days
7.5
7.5

Hi there, To build a Coordinated Vulnerability Disclosure system, I would leverage a combination of open-source components to create a robust workflow for managing reported vulnerabilities. The key functionalities, such as a clean interface for ticket management, role-based access, and encrypted data storage, will be integrated seamlessly. Choosing frameworks and libraries optimized for a Linux server aligns perfectly with your deployment requirements. I will deliver the complete source code in a repository with a one-command deployment script—and concise documentation to ensure you can manage installations effortlessly. Your satisfaction is my priority and I guarantee that I will deliver you a high-quality result. Regards, Ali
$5,000 USD in 14 days
6.4
6.4

A CVD platform is really a ticketing engine wearing security clothes: intake, triage, assignment, fix verification, disclosure timeline. Writing that state machine from a blank editor means re-solving problems tools like Zammad or osTicket already handle well, on someone else's budget. My plan is to start from a base like that, strip what doesn't apply, and add the security-specific layer on top: TOTP MFA for researchers, engineers and third parties, role scoped views so a researcher never sees another report, full audit logging on every state change, and attachments encrypted at rest with per-report keys rather than one shared secret. It all ships as source plus a single Ansible playbook and docker-compose file, so your fresh-VM acceptance test is just running one command and walking a sample report end to end, not chasing missing dependencies. M1: architecture, base platform selection and hardening plan, $1700, 4 days. M2: ticketed disclosure workflow and role-based access, $1900, 5 days. M3: MFA, audit trail and encrypted attachment storage, $1900, 5 days. M4: Ansible/Docker one-command deploy packaging, $1500, 4 days. M5: documentation, fresh-VM acceptance run and handover, $1500, 3 days. Two things before I lock the base platform: do you want a helpdesk-style base like Zammad, or something closer to a plain issue tracker, and does "third parties" mean vendors get their own login or just a shared reporting inbox?
$8,500 USD in 21 days
6.5
6.5

Using my extensive knowledge of multiple programming languages like PHP, Python, Node.js, Java and others - I have the ability to select, integrate and create a secure Environment for your project. I'll ensure that your CVD system runs smoothly on a Linux server by implementing the most appropriate and well-supported frameworks from open-source bug bounty platforms, ticketing systems, and secure messaging stacks. With special proficiency in web development technologies such as HTML, CSS, JavaScript, React and so on, I'll build for you a clean and user-friendly web interface that meets your ticket submission management needs. In addition to my core tech skills, I understand the importance of clean code and data security. I guarantee secure data storage with encryption for sensitive attachments and notes that is so essential for your chosen CVD project. As a Full-stack developer with over 10 years of experience , I've tackled different challenging projects similar to this in the past which has armed me with the knowledge needed to accomplish this way beyond any prescribed script deployment instruction. Being able to efficiently manage databases using MySQL, PostgreSQl, MongoDB is an added advantage in ensuring smooth vulnerability workflow management for your project. Notably so,I've successfully handled various SaaS platforms that require custom process flows and good UI design-resulting in satisfied clients.
$5,000 USD in 1 day
6.5
6.5

Your MFA requirement will fail if you rely on basic TOTP plugins—most open-source ticketing systems lack native support for hardware keys or push-based authentication, which means you'll need a reverse proxy like Authelia or Keycloak sitting in front of the app. This adds deployment complexity and potential session-handling conflicts. Quick questions - are you planning to federate MFA with an existing identity provider like Okta or Azure AD? And what's your expected volume of concurrent vulnerability reports during a disclosure event? Here is the architectural approach: - DOCKER + ANSIBLE: Multi-container stack with PostgreSQL backend, Redis for session management, and Nginx reverse proxy; Ansible playbook handles secrets injection and SSL cert provisioning in one command. - PHP + LARAVEL: Custom CVD workflow engine built on Laravel with role-based ACL middleware, encrypted file storage using AWS KMS or Vault integration, and immutable audit logs stored in separate append-only tables. - MFA + RBAC: Authelia container enforcing hardware key support (WebAuthn/U2F) before app access; granular permissions let researchers see only their own reports while internal teams access full triage queues. I've built similar secure disclosure platforms for two healthcare SaaS companies that passed SOC2 audits on first attempt. Let's schedule a 20-minute call to walk through the container architecture before you commit to a build.
$6,750 USD in 30 days
6.4
6.4

Hi, You're aiming for an open-source CVD platform with strong RBAC, audit trails, encryption, and a Linux stack. That footprint matches work I've done building risk-aware ticketing and workflow dashboards using open-source components in similar environments, where MFA and scoped access matter for researchers, engineers, and responders. Execution approach: I’d start by validating the current flow, lock down RBAC, attach an immutable audit trail, and propagate encryption for attachments and notes. A one-command Docker deployment with a minimal Ansible playbook for config would get you to a test VM quickly, followed by real usage validation with a sample vulnerability report. One technical risk: maintaining data integrity and encryption across the multi-tenant audit log during updates. Two clarification questions: - What MFA method and user-store should govern authentication, and how will you provision/test accounts? - How should we handle retractions or reopens of reports during the workflow? If we're aligned, I can outline the implementation plan before we get started. Best regards, Brandon
$7,000 USD in 40 days
6.0
6.0

Hello! I see you’re looking to build a Coordinated Vulnerability Disclosure (CVD) system using open-source components. That’s a crucial initiative for enhancing security and transparency. With my extensive experience in PHP, MySQL, and Docker, I can help you design a robust architecture that meets the requirements of your project while ensuring scalability and maintainability. My background in software development, along with over a decade of project management experience, equips me to navigate both the technical and strategic aspects of this project. I understand the importance of integrating various components seamlessly and am familiar with the best practices in open-source development. Let’s collaborate on creating a CVD platform that not only meets your goals but also fosters community trust and engagement. I’m eager to bring your vision to life. Looking forward to the possibility of working together! Clarification Questions: 1. What specific features or functionalities do you envision for the CVD platform that might not be covered in the description? 2. Are there any specific compliance or regulatory requirements we need to consider during development? 3. How do you plan to handle the notification process for vulnerabilities reported through the system?
$7,500 USD in 48 days
6.6
6.6

Macedonia
Payment method verified
Member since Mar 12, 2024
€750-1500 EUR
$250-750 USD
₹1500-12500 INR
₹1500-12500 INR
₹600-1500 INR
$10-30 USD
$12-30 SGD
£250-750 GBP
$15-25 USD / hour
₹1500-12500 INR
$30-250 USD
$30-250 USD
₹35000-50000 INR
₹600-1500 INR
$30-250 USD
₹12500-37500 INR
$10-30 AUD
₹12500-37500 INR
₹1500-12500 INR
$250-750 USD
₹1500-12500 INR
$8-15 USD / hour