IstroSec s.r.o. (hereinafter referred to as the “Company”) takes the security of its products with digital elements seriously and, in accordance with the EU Cyber Resilience Act (CRA), establishes a single point of contact for vulnerability reporting.
1. Contact Information
Email: [email protected]
Encryption: PGP key of IstroCSIRT
Fingerprint 7B32BC0318E646CA6E9169A25F11C27756920C70, available at https://istrosec.com/files/IstroCSIRT_0x56920C70_public.asc
Supported languages: English, Slovak
The contact point is monitored by humans, not solely by automated tools.
2. What the Report Should Include
- A description of the vulnerability and its estimated/potential impact
- Steps to reproduce (detailed steps, PoC, screenshots/video where applicable)
- Affected product / version / URL
- Whether you know or suspect that the vulnerability is being actively exploited
- Your contact details (for follow-up, feedback)
3. Coordinated Disclosure (Embargo)
We kindly request that the reporter not disclose the vulnerability publicly before the Company implements a fix, or until an agreed-upon date (typically up to 90 days from the initial report, unless otherwise agreed by both parties). The coordinated disclosure date will be agreed upon directly with the reporter.
4. Safe Harbor
The Company will not pursue legal action against reporters who act in good faith, act reasonably, and comply with this policy when discovering and reporting a vulnerability. Acting reasonably means in particular testing only systems you own or are authorised to test (this policy does not authorise testing of systems operated by the Company’s customers), accessing data only to the extent necessary to demonstrate the vulnerability, and not disrupting any service.
5. Legal Basis
This policy is established in accordance with Article 13(11), Article 14, and Annex II Article 13(8) and 13(17), Article 14, Annex I Part II points 4 to 6, and Annex II point 2 of Regulation (EU) 2024/2847 (Cyber Resilience Act).