Coordinated vulnerability disclosure
Security research is part of how we work, and it sometimes uncovers vulnerabilities in products we don't control. When that happens, we coordinate with the people who can fix them. Our goal is to reduce public risk and act in the long-term interest of the broader community. We also welcome vulnerability reports from others – this page covers both.
Reporting a vulnerability to us
If you believe you've found a security or privacy issue in anything we build or operate, we want to hear from you. Email security@stratigossecurity.com with enough detail for us to reproduce the issue: the affected system or product, the steps you took, and any proof-of-concept material you can share.
What you can expect from us:
- We'll acknowledge your report within seven days.
- We'll keep you informed as we confirm, remediate, and disclose the issue.
- We'll credit you for the discovery if you'd like, or keep your involvement confidential if you prefer.
- We will not pursue or support legal action in response to good-faith security research that avoids harm to people, data, and services.
We also help unaffiliated researchers navigate coordinated disclosure with other vendors. If you've found something and aren't sure what to do next, contact us and we'll help you work through it.
When we find vulnerabilities
We believe security research works best when every party acts on its own judgment. We operate transparently with vendors and document our procedures. We don't substitute our judgment for anyone else's, and we expect the same respect in return. Our policy prioritizes the interests of our clients, our firm, and the general public – which may mean disclosing vulnerability information publicly or privately.
Our coordinated disclosure process
- We discover, review, and confirm the vulnerability.
- We draft a notification and send it to the vendor's security contacts.
- We notify other relevant parties (such as CISA, CERT/CC, and MITRE) where appropriate.
- We work with the vendor to establish timelines, milestones, and remediation processes.
- The vendor develops a fix, publishes an update, and notifies customers.
- We release a brief discovery statement.
If a vendor is unresponsive or acts contrary to the public interest, we reserve the right to disclose the vulnerability publicly or privately without further notice.
Disclosure documentation
Our standard notifications include:
- Internal and external tracking codes
- CVSS v4.0 severity scores
- Affected vendor(s), product(s), and versions
- Discovery and reporting dates
- Current status
- Issue summaries and details
- Proof-of-concept validation procedures
- Root cause analysis
- Potential effects
- Recommendations for affected parties
Resources
Our practice aligns with these standards and community resources:
- Establishing a CVD Program to Work with Security Researchers – joint guide from CISA and international partners (2026)
- disclose.io – standardized safe harbor and disclosure policy framework
- ISO/IEC 29147 – Vulnerability disclosure
- ISO/IEC 30111 – Vulnerability handling processes
Building a coordinated disclosure program for your own product?
We help device manufacturers stand up coordinated disclosure programs that meet regulatory expectations and that researchers actually want to engage with.