Securityeralytics: Coordinated Vulnerability Disclosure Policy

Purpose

eralytics welcomes reports of security vulnerabilities in our products from customers, researchers, and the public. This policy describes how to report a vulnerability to us, what to expect from that process, and the scope it covers. It exists to satisfy the Coordinated Vulnerability Disclosure requirement of Regulation (EU) 2024/2847 (the Cyber Resilience Act), Annex I, Part II, and to give external reporters clear, good-faith terms for engaging with us.

Scope

In scope:

  • eralytics laboratory instruments running EraOS
  • The remote-support channel (‘service.eralytics.com’) and its authentication.

Out of scope:

  • Denial-of-service testing against production instruments or the remote-support infrastructure.
  • Physical/hardware attacks requiring prior root or physical possession of a device already trusted by its owner (e.g. a customer’s own unlocked unit) – still welcome as a report, but not treated as an emergency-severity finding by default.
  • Third-party dependencies’ own upstream disclosure processes (report to the upstream project; let us know too if it affects a shipped version so we can track remediation).

How to report

Email ‘security@eralytics.com’ with:

  • A description of the vulnerability and its potential impact.
  • Affected product(s) and firmware/software version(s) (required, if known).
  • Steps to reproduce, proof-of-concept code, or relevant logs.
  • Whether you intend to publicly disclose, and any timeline you have in mind.

Please do not open a public GitHub issue, forum post, or social media report for a suspected vulnerability before we’ve had a chance to respond.

We don’t currently offer PGP encryption for reports – plain email is the baseline most CVD programs use. If encrypted reporting is wanted later, generate a real keypair on infrastructure eralytics controls (the private key must stay with whoever will hold it) and add the public key and its fingerprint here and in `security.txt` at that time.

Our commitment

MilestoneTarget
Reporting receiptWithin 3 business days
Initial triage/severity assessmentWithin 10 business days
RemediationTimeline depends on severity and complexity – see §5

We will keep you informed of progress, credit you (if you want to be credited) once a fix ships, and let you know when it’s safe to publicly disclose.

Remediation and disclosure timeline

Fixes are delivered via signed RAUC OTA image updates or, for single-app fixes, the ‘apt’-based delta update path – both mechanisms already in place in EraOS, at no cost to the device owner.

Default coordinated disclosure window: 90 days from acknowledgment, or until a fix is available and deployed, whichever is later. We may ask for a reasonable extension if remediation requires a hardware-adjacent change or
affects multiple product lines.

If a reported vulnerability is already under active exploitation, we will prioritize an emergency fix and will not ask for an extension to the disclosure window on that basis.

Safe harbor

We will not pursue legal action against researchers who:

  • Make a good-faith effort to avoid privacy violations, data destruction, and service disruption during their research.
  • Only interact with instruments they own or have explicit permission to test.
  • Report the vulnerability to us promptly and do not exploit it beyond what’s necessary to demonstrate the issue.
  • Give us a reasonable opportunity to fix the issue before any public disclosure.