AnnexProof

Vulnerability disclosure policy

If you find a vulnerability in AnnexProof, please tell us. This is how we handle vulnerabilities in our own product, in line with the good practice the Cyber Resilience Act expects from manufacturers.

1. Scope

2. How to report

Write to security@annexproof.com, in English or Polish. These help us most:

Our PGP key is available on request. The same address is in /.well-known/security.txt.

3. What we do after you report

4. Good-faith research

We will not take legal action against people who look for vulnerabilities in good faith and follow this policy. Good faith here means you do not harm our users, you do not disrupt the service, and you give us time to fix the issue before you describe it publicly. This commitment is ours; we cannot speak for other companies or authorities.

5. Out of scope

6. Vulnerabilities in our customers' products

This channel is for AnnexProof itself. To report a vulnerability in another manufacturer's product, including one of our customers, contact that manufacturer directly: through its PSIRT page, its CVD policy or its security.txt file. You can look these up with the CRA Snapshot.