The French version is the official one. This English text is a courtesy translation.
Security
Coordinated disclosure policy
Last updated: 21 August 2026
CRAFT sells product vulnerability management. This page is the procedure for reporting a flaw in CRAFT itself. Please do not publish an exploit until we have been able to fix it.
01Scope
This policy covers the website craftsec.eu and the services associated with the prototype (SBOM analysis, public pages). It does not cover our users’ products, nor vulnerabilities present in an uploaded SBOM.
02How to report
- Contact
- contact@craftsec.eu
- Languages
- French, English
Include, if possible: the URL or component concerned, the reproduction steps, the estimated impact, and whether a fix seems obvious to you. A formal report is not required.
03Our commitments
- Acknowledgement of receipt within 72 hours.
- Assessment and, where applicable, a fix within a reasonable period depending on severity.
- Coordination of publication: we prefer a period of 90 days after the report, adjustable by mutual agreement.
- Public credit if you wish, once the fix is live.
We do not offer a bug bounty at this time. A good-faith report, without exfiltration of others’ data or service interruption, will not be the subject of legal action on our part.
04Out of scope
Aggressive automated scanning, denial of service, social engineering towards third parties, and access to other users’ SBOMs are excluded. The prototype does not retain uploaded files: there is no store of customer SBOMs to test.