Trust Centre
Trust · Veritome

Vulnerability disclosure policy

Last updated 30.08.2026
Ahead of the Cyber Resilience Act (EU) 2024/2847 taking full effect, Veritome maintains a coordinated vulnerability-disclosure policy. We welcome responsible security research from the community.

Our commitment

Veritome is committed to the security of our platform and the data our customers entrust to us. We welcome and encourage responsible security research and vulnerability disclosure from the security community. This policy sets out how to report vulnerabilities and what you can expect from us.

Scope

This policy applies to vulnerabilities in:

  • The Veritome web application (app.veritome.eu)
  • Veritome REST APIs (app.veritome.eu/api)
  • The Veritome public website (veritome.eu)
  • Supporting infrastructure directly operated by Veritome

Out of scope: third-party services (Stripe, Mistral, Hetzner, Resend, Sentry, PostHog), social engineering, denial-of-service attacks and physical security.

How to report

Email
security@veritome.eu

When reporting a vulnerability, please include:

  • A clear description of the vulnerability and its potential impact
  • Detailed steps to reproduce the issue
  • The affected component (URL, API endpoint, feature)
  • Your assessment of severity (critical / high / medium / low)
  • Any proof-of-concept code or screenshots

For sensitive reports, you may encrypt your message with our PGP key at https://veritome.eu/.well-known/pgp-key.asc

Response commitments

Acknowledge receipt48 hours
Initial triage and severity assessment5 business days
Patch for critical severity30 calendar days
Patch for high severity60 calendar days
Patch for medium and low severity90 calendar days
Public disclosure (after patch)Coordinated with reporter

Safe harbour

We will not pursue legal action against security researchers who:

  • Act in good faith and follow this disclosure policy
  • Avoid accessing, modifying or deleting data belonging to other users
  • Do not exploit the vulnerability beyond what is necessary to demonstrate it
  • Report the vulnerability promptly and allow reasonable time for remediation
  • Do not publicly disclose the vulnerability before a patch is available

Recognition

We recognise security researchers who help us protect our platform and our customers. With your permission, we will acknowledge your contribution on this page. We do not currently offer a monetary bug bounty programme, but may introduce one in the future.

Cyber Resilience Act

This policy is maintained with reference to Article 11 of the Cyber Resilience Act (EU) 2024/2847, which requires manufacturers of products with digital elements to establish and maintain a coordinated vulnerability disclosure policy. Actively exploited vulnerabilities will be reported to ENISA within 24 hours as Article 14(2)(a) requires.

General security enquiries: security@veritome.eu ·  Data protection enquiries: dpo@veritome.eu