It really would make great sense to create an 'report exploits' link on your site/software so that people know they can freely contact you about this kind of thing without repercussions. I actually got one about 2 days ago for a forum I coded because of such a link I put there.
It might be interesting to even make a whole website dedicated to exploit hunting and allow companies to register themselves.