Coordinated Vulnerability Disclosure (CVD) Policy

V1.0

Pursuant to Annex I Part 2(5)(6) and Article 13

Article 1 — Purpose and Basis

This Policy establishes a public and trustworthy mechanism for reporting and coordinated disclosure of security vulnerabilities, fulfilling the obligations under Annex I Part 2(5) (put in place and enforce a CVD policy) and (6) (provide a contact address for reporting vulnerabilities) CRA.


Article 2 — Scope

This Policy applies to security vulnerabilities discovered in the products with digital elements placed on the Union market by the Company (the “Products”) and in third-party components contained therein.

Article 3 — Reporting Channel

Single point of intake: (1) security@[company domain]; (2) the online report form. A security.txt file (RFC 9116) is published at the website root. PGP encryption is supported (fingerprint: [PGP Fingerprint]).

Article 4 — Information to Include

Please provide, per the Security Vulnerability Report Form: affected product and version, vulnerability summary and steps to reproduce, impact and severity, disclosure status, and contact information. Reporters may remain anonymous.

Article 5 — Handling Process

The Company handles reports as follows: (a) acknowledge receipt; (b) triage and validate; (c) develop and distribute a fix (security update); (d) coordinate disclosure (see Article 9). Vulnerabilities in third-party components are reported back to the respective supplier.

Article 6 — Response Timeframes

Receipt is acknowledged within [5] working days; triage outcome and remediation timeline are communicated within [15] working days. Severe vulnerabilities (actively exploited or high severity) are prioritised and security updates provided without undue delay.

Article 7 — Safe Harbour

For reporters acting in good faith and in compliance with this Policy (performing only necessary validation, not causing damage, not disclosing others' data, and not publishing details before coordinated disclosure), the Company undertakes not to initiate legal proceedings and to support them against third-party claims.

Article 8 — Anonymity and Confidentiality

Reporters may report anonymously. The Company keeps reporter identity and vulnerability details confidential, sharing them only to the extent necessary to perform its legal obligations or coordinate remediation.

Article 9 — Disclosure Timeline and Principles

Following the “patch before disclose” principle, information on fixed vulnerabilities (deion, affected products, impact, severity and remediation guidance) is publicly disclosed once a security update is available. In duly justified exceptional cases, disclosure may be delayed until users have had the opportunity to apply the patch.

Article 10 — Interface with Statutory Reporting

Where a reported issue constitutes an “actively exploited vulnerability” or a “severe incident” under Article 14 CRA, the Company will report it within the 24h/72h/final deadlines via the ENISA Single Reporting Platform, with the EU Authorised Representative acting on its behalf where applicable.

Article 11 — Recognition

[Optional] The Company may credit valid reports that are confirmed and contribute to remediation (and reward them under a published bug-bounty programme where applicable). Recognition does not affect the safe-harbour and confidentiality commitments above.

Article 12 — Review and Updates

This Policy is reviewed at least annually and updated as needed upon changes to products, processes or regulation. Updated versions are published on the website with an effective date.

 

Contact

Security email: psirt@infypower.com
PGP fingerprint: [F6B59934E5B3EBE51FB02869164BCF63D4C8A1CC]
Effective date: [11 September 2026]