Coordinated vulnerability disclosure policy
Template version 2026-08-14 Effective date: 25-08-2026
Purpose and scope
CRA Desk welcomes reports of security vulnerabilities in its products. This policy explains how to report a vulnerability, what to expect after reporting and the timeline we follow for coordinated disclosure.
It covers the CRA Desk service at cradesk.eu, its API and scheduled workloads and the CI scanner we distribute for GitHub and GitLab.
How to report a vulnerability
Report a suspected vulnerability to security@cradesk.eu. Include a description of the issue, the affected product and version and steps to reproduce it where known.
Please do not open a public issue in the scanner's repository for a security report and do not include third-party data in a proof of concept.
What to expect after reporting
We acknowledge reports within 5 business days, keep the reporter informed of remediation progress and credit the reporter in our advisory unless anonymity is requested.
We do not operate a paid bug bounty.
Safe harbor for good-faith research
Good-faith security research conducted under this policy, without accessing or modifying data beyond what is necessary to demonstrate the vulnerability, will not be pursued as unauthorised access.
This covers our own systems only. It cannot and does not waive the rights of our customers, our sub-processors, or any third party - so testing that would reach a customer's data is outside it.
Coordinated disclosure timeline
We aim to remediate confirmed vulnerabilities and coordinate public disclosure with the reporter within 90 days of the initial report, or sooner where the vulnerability is actively exploited.
Sections and citations: Regulation (EU) 2024/2847, Annex I, Part II, points 5 and 6.