Last updated: 2026-08-02. This policy is reviewed at least once a year.
1. Introduction & Scope
This Coordinated Vulnerability Disclosure (CVD) policy applies to all products and services developed and maintained by Aurelia Devices B.V..
We consider the security of our systems and the data of our users to be of paramount importance. This policy is designed to ensure a secure, transparent, and legally protected environment for security researchers to report vulnerabilities, in full compliance with the EU Cyber Resilience Act (CRA).
2. EU CRA Alignment
Pursuant to Article 13 (Vulnerability handling requirements) and Article 14 (Reporting obligations of manufacturers) of the Cyber Resilience Act, Aurelia Devices B.V. commits to:
- Actively manage and remediate actively exploited vulnerabilities and severe security incidents.
- Share upstream any vulnerabilities discovered in integrated third-party components to the maintaining entity.
- Submit an early warning to ENISA and the designated national CSIRT within 24 hours of becoming aware of an actively exploited vulnerability (Article 14(2)(a)).
- Submit a full vulnerability notification within 72 hours providing general information on the exploit and any corrective measures (Article 14(2)(b)).
- Submit a final report within 14 days after a corrective or mitigating measure becomes available (Article 14(2)(c)).
3. Reporting Protocol & Safe Harbor
To maintain Safe Harbor status and clear legal protection, you must submit your findings securely through our portal.
Our assurances to you:
- Your report is treated confidentially to the extent permitted by law.
- Your personal data will not be shared with third parties without your explicit consent.
- We will not pursue criminal charges or civil action against you for good-faith research conducted in line with this policy.
- We will never require you to sign a non-disclosure agreement as a condition of reporting or coordination.
- If you wish, we will credit you by name or alias once the vulnerability is resolved.
Anonymous reporting: You may submit a report without providing any contact details via the Secure Disclosure Form. We minimise metadata for anonymous reports and do not retain your IP address. Please note that anonymous reports can only be processed to a limited extent if we cannot reach you with technical follow-up questions.
Submission Guidelines:
- All reports must be submitted via the Secure Disclosure Form.
- Please provide a detailed technical breakdown, clear steps to reproduce (PoC), and any relevant scripts used.
- We strongly recommend encrypting sensitive findings using our provided PGP Public Key below.
Authorized Testing:
- Research exclusively targeting products actively deployed and managed by Aurelia Devices B.V..
- Non-disruptive testing focused on identifying flaws without compromising user privacy or service availability.
Prohibited Actions (Strictly Forbidden):
- Introducing Malware: Placing malware, backdoors, web shells, or any other malicious code on our systems.
- Copying, Editing, or Deleting Data: Accessing, disclosing, copying, modifying, or deleting data belonging to other users. A directory listing or minimal proof of access is sufficient evidence.
- System Changes: Making changes to the system or its configuration beyond what is strictly necessary to demonstrate the vulnerability.
- Repeated or Shared Access: Repeatedly accessing the system after the vulnerability has been demonstrated, or sharing the access you obtained with others.
- Brute-Force Attacks: Password guessing, credential stuffing, or other brute-force attempts to gain access to systems or accounts.
- Denial of Service (DoS): Any payload or action that degrades service availability.
- Social Engineering: Phishing, vishing, or physical access attempts against our employees.
4. Expectations & Service Level Agreements
We follow standard guidelines (ISO/IEC 29147 and BSI TR-03183-3) for coordinated disclosure. By reporting a vulnerability to us, you can expect:
- Acknowledgment: We will acknowledge receipt of your report within 48 hours. This response is written by a person, never an automated reply, and always within five working days.
- Triage & Validation: We will provide an initial assessment of the vulnerability within 10 business days, and detailed feedback in any case within ten working days. This feedback confirms or rejects the reported vulnerability, or explains why the investigation needs more time together with a committed date for the next update.
- Status Updates: Transparent updates on our remediation progress at least every 15 calendar days.
- Coordinated Public Disclosure: We publicly disclose validated and verified vulnerabilities within 90 days, in coordination with you. Where a justified reason exists (for example a patch that requires more time), we may agree on a different timeline and will document the reason.
Contact Information: For any questions regarding this policy or the disclosure process, please contact our security team at [email protected]. We accept email and telephone contact options for follow-up communication.