Security & Vulnerability Disclosure

Help us keep ThreatZ secure

We take the security of the ThreatZ platform seriously. If you have discovered a vulnerability or believe you have, we’d like to hear about it through coordinated disclosure.

Security contact

LanguagesEnglish, German
Disclosure file/.well-known/security.txt (RFC 9116)
EncryptionPGP key available on request

In scope

The following are within scope for coordinated disclosure:

Out of scope

How to report

  1. Email security@uraeus.io with a clear description of the issue.
  2. Include steps to reproduce, affected component(s), and the impact you believe is demonstrable.
  3. Attach screenshots, request/response captures, or proof-of-concept code as appropriate.
  4. If the issue is sensitive, request our PGP key in your first email and we will reply with it.
  5. Allow us reasonable time to investigate and remediate before any public disclosure.

Our response commitment

When you report a vulnerability in scope, we commit to the following triage SLAs:

Vulnerability triage SLAs by severity
SeverityFirst responseTriage decisionRemediation target
Critical1 business day2 business days7 calendar days
High2 business days5 business days30 calendar days
Medium5 business days10 business days90 calendar days
Low10 business days20 business daysNext scheduled release

Severity is assigned using CVSS 3.1 (Base) and adjusted for environmental factors specific to the ThreatZ platform.

Safe harbor

When you act in good faith under this policy:

This safe harbor does not authorize: accessing customer data, modifying customer data, disrupting service for other users, or any activity that would violate applicable law. If in doubt about an action, contact us first.

CSMS & coordinated disclosure obligations

ThreatZ’s own engineering operates under a coordinated disclosure process aligned with ISO/SAE 21434 §15.4 (Cybersecurity incident response). Customers operating ThreatZ inside a CSMS programme can map our incident-response process to their own UNECE R155 §7.3.3 obligations and request our supporting playbook as part of procurement review.

Acknowledgments

We are grateful to the researchers who have responsibly reported vulnerabilities to us. With permission, we publish acknowledgments here.

List forthcoming — we acknowledge new contributors as reports are resolved and reporters consent to public recognition.