CVEasy AI ยท Research
Security research and coordinated disclosure
CVEasy AI Research finds and reports vulnerabilities as part of building the exploit-intelligence layer behind our platform. When we find something in your product, this page describes exactly what happens next.
Our disclosure policy
- Vendor first. We contact the affected vendor privately at their published security contact before any public disclosure.
- 90-day window. We hold details for 90 days from first contact, or until a fix ships, whichever comes first. We extend for vendors actively working a fix; we may shorten if the flaw is being exploited in the wild.
- CVE assignment. We request a CVE through the vendor's CNA when one exists, otherwise through MITRE. Research is credited to CVEasy AI Research and the individual researcher.
- Public advisory. After the window closes we publish a technical advisory on our blog with the timeline, mechanism, and remediation guidance.
Vendors: reach us
If we contacted you about a vulnerability, or you want to reach the research team, email christopher@cveasyai.com with the CVE ID or advisory reference in the subject.
Published advisories
Advisories appear on the CVEasy AI blog as they are released.