Research · Coordinated disclosure

Security research and coordinated disclosure.

CVEasy AI Research finds and reports vulnerabilities as part of building the exploit-intelligence layer behind the platform. When we find something in your product, this page describes exactly what happens next.

The disclosure clock

One clock, started the day we contact the vendor.

The window runs up to 90 days from first private contact, or until a fix ships, whichever comes first. It extends while a vendor is actively working a fix, and shortens if the flaw is already being exploited in the wild.

Coordinated window · up to 90 days → extends while a fix is in progress → shortens if exploited in the wild Day 0 Vendor contacted private security contact During window CVE requested CNA, or MITRE · credited to research + researcher Day 90 or fix ships Public advisory blog · timeline + mechanism + fix

Whichever comes first: the 90th day, or the day the fix is public.

01 · How we disclose

Our disclosure policy.

Four commitments, applied to every flaw the research team reports, from a single-vendor bug to a widely used component.

01

Vendor first

We contact the affected vendor privately at their published security contact before any public disclosure.

02

90-day window

We hold details for 90 days from first contact, or until a fix ships, whichever comes first. We extend for vendors actively working a fix; we may shorten if the flaw is being exploited in the wild.

03

CVE assignment

We request a CVE through the vendor's CNA when one exists, otherwise through MITRE. Research is credited to CVEasy AI Research and the individual researcher.

04

Public advisory

After the window closes we publish a technical advisory on our blog with the timeline, mechanism, and remediation guidance.

02 · Vendors

Reach the research team.

If we contacted you about a vulnerability, or you want to open a line to the team, one address handles it.

If we contacted you about a vulnerability

Email christopher@cveasyai.com with the CVE ID or advisory reference in the subject, and the thread stays with the researcher who filed it.

Email research →
03 · Published advisories

Advisories land on the blog as they release.

Each one carries the full timeline, the mechanism, and the remediation steps, once the disclosure window has closed.

Research announcements land first on the CVEasy AI LinkedIn page and the free threat-intel bundle, then the technical write-up follows on the blog.