Vulnerability Disclosure Policy
Guidelines for responsible reporting, coordinated disclosure timeframes, and safe-harbor research protocols.
POLICY STANDARD: ISO/IEC 29147 ALIGNED | LEAD REVIEWER: ADMIN
1. Coordinated Disclosure Stance
UnpanicTech supports the global cybersecurity defense ecosystem through strict adherence to Coordinated Vulnerability Disclosure (CVD). We believe that public safety and data protection are best served when vendors and maintainers are given a reasonable, defined window to produce and deploy remediation patches before technical details are published.
2. Publishing Thresholds & Timelines
When our analysts investigate third-party zero-day vulnerabilities or security flaws:
- Standard 90-Day Embargo: Vulnerability notifications are delivered directly to the designated vendor security contact with a standard 90-day timeline before public editorial disclosure.
- Active Exploitation Threshold: If reliable evidence indicates that a vulnerability is actively being exploited in the wild by threat actors, disclosure timelines may be accelerated to provide defensive workarounds and Sigma detection signatures to the community.
- Zero Weaponization Policy: We never distribute compiled weaponized payloads, automated intrusion toolkits, or exploits configured for turnkey compromise.
3. Reporting Security Flaws on UnpanicTech
If you discover a security flaw or technical misconfiguration affecting UnpanicTech infrastructure:
Safe Harbor Researcher Pledge:
We will not pursue civil action or report security researchers to law enforcement if your research activities are conducted in good faith, avoid privacy violations, prevent service degradation, and afford us reasonable opportunity to address the finding.
4. Submission Process
Security researchers and vendor teams can dispatch findings directly through our Contact Desk or via email to naseemkhannasar7@gmail.com. Please include:
- Affected service, repository, or CVE identifier.
- Step-by-step reproduction instructions and benign proof of concept.
- Your preferred attribution handle or public pseudonym.
Our security desk strives to acknowledge received disclosure transmissions within 48 business hours.