
Researchers report through a public form or by email. Attachments go into quarantine and every report is correlated against known vulnerabilities. When the same finding is reported more than once, every report is kept and the reports are linked to one another. An analyst then reviews it and forwards it to the address on file.
The company maintains its own security.txt and disclosure policy and publishes them under its own domain. The domain is verified through a DNS record, and the publication is checked for drift from then on. Both follow open standards: RFC 9116, and a specification that belongs to nobody.