AnnexProof
Vulnerability disclosure policy
If you find a vulnerability in AnnexProof, please tell us. This is how we handle vulnerabilities in our own product, in line with the good practice the Cyber Resilience Act expects from manufacturers.
1. Scope
- annexproof.com (this website),
- app.annexproof.com (the app),
- the AnnexProof service.
2. How to report
Write to security@annexproof.com, in English or Polish. These help us most:
- the affected URL or component;
- steps to reproduce the issue;
- the impact: what an attacker could do with it;
- your contact details, and whether you would like to be credited by name.
Our PGP key is available on request. The same address is in /.well-known/security.txt.
3. What we do after you report
- We acknowledge your report within 3 business days.
- We triage the issue and update you on progress at least every 14 days.
- We agree disclosure with you. By default we publish details 90 days after the report, or earlier once a fix is deployed.
- With your consent, we credit you as the person who reported the issue.
- We do not run a bug bounty programme and do not pay rewards for reports.
4. Good-faith research
We will not take legal action against people who look for vulnerabilities in good faith and follow this policy. Good faith here means you do not harm our users, you do not disrupt the service, and you give us time to fix the issue before you describe it publicly. This commitment is ours; we cannot speak for other companies or authorities.
5. Out of scope
- Denial of service (DoS) and volumetric or load testing.
- Social engineering and phishing, against us or our customers.
- Physical attacks.
- Spam, and automated scanner output without a demonstrated impact.
- Accessing or changing other people's data beyond what is needed to demonstrate the issue. If you come across someone else's data, stop and report it to us.
6. Vulnerabilities in our customers' products
This channel is for AnnexProof itself. To report a vulnerability in another manufacturer's product, including one of our customers, contact that manufacturer directly: through its PSIRT page, its CVD policy or its security.txt file. You can look these up with the CRA Snapshot.