Respectfully, I'm going to default back to what I said.
The "notify in good faith" really just fosters a culture of "scratch my back, i'll scratch yours". Frankly, as a white-hat researcher you can be as much of a bad actor as any company and this is a sort of moral hazard that fosters a culture of unfairness and insecurity. If you really care about the overall security of the industry or consumers, you will publish immediately and leave the moral hazard of "perks/special treatment" off the table.
The companies that are reasonable in the way that you describe would not be materially harmed by such a disclosure and do not (okay, rarely) have the most egregious kinds of bugs. It raises the bar for everyone to do this.
Basically, it's not about you; don't make it about you; just publish. Every day that you do not publish, some client could be catastrophically affected by the bug and the company could be seriously dragging-ass on the fix. You have no visibility into this.
(Side note: I'm a developer and I build all of my infrastructure. Getting caught with my pants down by a vulnerability disclosure would totally fucking suck and be 100% my fault. It's my neck on the line. So yes, it will suck, and I might hate you a little, but then I'll realize it's my screw-up and that I need better processes to proactively solve these.)
The "notify in good faith" really just fosters a culture of "scratch my back, i'll scratch yours". Frankly, as a white-hat researcher you can be as much of a bad actor as any company and this is a sort of moral hazard that fosters a culture of unfairness and insecurity. If you really care about the overall security of the industry or consumers, you will publish immediately and leave the moral hazard of "perks/special treatment" off the table.
The companies that are reasonable in the way that you describe would not be materially harmed by such a disclosure and do not (okay, rarely) have the most egregious kinds of bugs. It raises the bar for everyone to do this.
Basically, it's not about you; don't make it about you; just publish. Every day that you do not publish, some client could be catastrophically affected by the bug and the company could be seriously dragging-ass on the fix. You have no visibility into this.
(Side note: I'm a developer and I build all of my infrastructure. Getting caught with my pants down by a vulnerability disclosure would totally fucking suck and be 100% my fault. It's my neck on the line. So yes, it will suck, and I might hate you a little, but then I'll realize it's my screw-up and that I need better processes to proactively solve these.)