CVEasy AI ยท Research

Security research and coordinated disclosure

CVEasy AI Research finds and reports vulnerabilities as part of building the exploit-intelligence layer behind our platform. When we find something in your product, this page describes exactly what happens next.

Our disclosure policy

  1. Vendor first. We contact the affected vendor privately at their published security contact before any public disclosure.
  2. 90-day window. We hold details for 90 days from first contact, or until a fix ships, whichever comes first. We extend for vendors actively working a fix; we may shorten if the flaw is being exploited in the wild.
  3. CVE assignment. We request a CVE through the vendor's CNA when one exists, otherwise through MITRE. Research is credited to CVEasy AI Research and the individual researcher.
  4. Public advisory. After the window closes we publish a technical advisory on our blog with the timeline, mechanism, and remediation guidance.

Vendors: reach us

If we contacted you about a vulnerability, or you want to reach the research team, email christopher@cveasyai.com with the CVE ID or advisory reference in the subject.

Published advisories

Advisories appear on the CVEasy AI blog as they are released.

Research announcements land first on the CVEasy AI LinkedIn page and the free threat-intel bundle.