CVEasy AI Research finds and reports vulnerabilities as part of building the exploit-intelligence layer behind the platform. When we find something in your product, this page describes exactly what happens next.
The window runs up to 90 days from first private contact, or until a fix ships, whichever comes first. It extends while a vendor is actively working a fix, and shortens if the flaw is already being exploited in the wild.
Whichever comes first: the 90th day, or the day the fix is public.
Four commitments, applied to every flaw the research team reports, from a single-vendor bug to a widely used component.
We contact the affected vendor privately at their published security contact before any public disclosure.
We hold details for 90 days from first contact, or until a fix ships, whichever comes first. We extend for vendors actively working a fix; we may shorten if the flaw is being exploited in the wild.
We request a CVE through the vendor's CNA when one exists, otherwise through MITRE. Research is credited to CVEasy AI Research and the individual researcher.
After the window closes we publish a technical advisory on our blog with the timeline, mechanism, and remediation guidance.
If we contacted you about a vulnerability, or you want to open a line to the team, one address handles it.
Email christopher@cveasyai.com with the CVE ID or advisory reference in the subject, and the thread stays with the researcher who filed it.
Each one carries the full timeline, the mechanism, and the remediation steps, once the disclosure window has closed.
Research announcements land first on the CVEasy AI LinkedIn page and the free threat-intel bundle, then the technical write-up follows on the blog.