IntervalZero’s Coordinated Vulnerability Disclosure (CVD) Policy
Last updated: 2026‑09‑03
Owner: IntervalZero, Inc.
This policy also serves as IntervalZero’s Vulnerability Disclosure Policy (VDP)
Purpose and Scope
IntervalZero is committed to identifying, assessing, and remediating cybersecurity vulnerabilities in its products and infrastructure in a transparent, responsible, and timely manner. IntervalZero maintains documented vulnerability handling processes for the entire lifecycle of its products and infrastructure, in accordance with the Cyber Resilience Act and applicable coordinated vulnerability disclosure standards.
This Coordinated Vulnerability Disclosure (CVD) Policy defines how IntervalZero receives, processes, coordinates, and discloses vulnerability reports in accordance with
- ISO/IEC 29147 (Vulnerability Disclosure)
- ISO/IEC 30111 (Vulnerability Handling)
This policy applies to:
- All IntervalZero products with digital elements
- IntervalZero‑operated services and infrastructure
Reporting a Vulnerability
Contact Options
Vulnerabilities may be reported using the following channels:
- Email (preferred): Security@intervalzero.com
- Send encrypted messages using the published OpenPGP public key in our security.txt.
- Our web reporting form
IntervalZero strongly recommends encrypted and digitally signed communication to ensure safety.
Anonymous Reporting
IntervalZero provides an option for anonymous vulnerability reporting via its web reporting interface.
Please note:
- Anonymous reports may be processed only to a limited extent.
- If follow‑up questions are required and no contact option exists, remediation may not be possible.
What Constitutes a Valid Vulnerability
A vulnerability is considered valid if it meets all the following conditions:
- It affects an IntervalZero product or IntervalZero‑operated infrastructure
- It is previously unknown or not publicly disclosed
- It is not solely the result of automated scanning without supporting technical analysis
Proof‑of‑concept (PoC) material, reproduction steps, and impact assessment are strongly encouraged.
Assurances to Security Researchers
IntervalZero provides the following assurances to all reporting entities acting in good faith:
- All reports are treated confidentially, subject to legal disclosure obligations
- Personal data of the reporter will not be disclosed without explicit consent
- IntervalZero will not pursue legal action against reporters who comply with this policy and act without criminal intent
- IntervalZero remains available for a trustful exchange throughout the CVD process
- With consent, reporters may be acknowledged publicly after completion of the CVD process
Code of Conduct for Reporting Entities
Security researchers are expected to:
- Avoid exploiting vulnerabilities beyond what is necessary for proof of concept
- Refrain from accessing, modifying, or exfiltrating personal or third‑party data
- Avoid service disruption (e.g. DoS, brute force, social engineering)
- Not offer exploit code to third parties or marketplaces
- Communicate respectfully and professionally
Reports will be reviewed even if these conditions are not fully met; however, non‑compliance may exclude eligibility for acknowledgements.
Response, Severity Classification, and Communication Timelines
IntervalZero follows a risk-based vulnerability handling process.
Validated vulnerabilities are classified based on severity, exploitability, and potential impact:
- Critical: Vulnerabilities with significant security impact, including vulnerabilities actively exploited in the wild
- High: Vulnerabilities with significant impact under realistic attack conditions
- Medium: Vulnerabilities with limited impact or requiring specific conditions
- Low: Vulnerabilities with minimal security impact
IntervalZero guarantees the following response times for non-anonymous reports:
- Initial response: within 5 working days (confirmation of receipt, non-automated)
- Detailed feedback: within 10 working days, including:
- Validation or rejection
- Follow-up questions
- Status update with revised timeline
Status enquiries from reporters are welcome at any time.
For vulnerabilities subject to Cyber Resilience Act (CRA) reporting obligations, including actively exploited vulnerabilities, IntervalZero follows applicable reporting timelines:
- Early warning notification: within 24 hours after becoming aware of active exploitation
- Vulnerability notification: within 72 hours after becoming aware of the vulnerability
- Final report: provided after completion of vulnerability analysis and remediation activities
Coordination and National CSIRT Involvement
For actively exploited vulnerabilities or vulnerabilities requiring CRA regulatory reporting, IntervalZero will:
- Notify the relevant national CSIRT or designated authority without undue delay
- Coordinate mitigation measures, timelines, and disclosures
- Provide updated information as remediation progresses
For vulnerabilities affecting multiple manufacturers, IntervalZero supports multi-party coordinated disclosure.
Vulnerability Disclosure
Validated and verified vulnerabilities are disclosed as follows:
- Public disclosure within 90 days after validation
- If justified, disclosure may be extended once by up to an additional 90 days, in coordination with the national CSIRT
- Security advisories may be published using the CSAF (Common Security Advisory Framework)
- Disclosure may occur via public advisories, customer notifications, or recognized vulnerability databases (e.g. EUVD)
Completion of the CVD Process
A CVD process is considered completed when one of the following applies:
- The vulnerability has been mitigated or fixed and disclosed
- The reported issue is determined to be invalid or unfounded
- The vulnerability is publicly disclosed and no feasible remediation exists
- The reporter has not responded to follow‑up requests for at least 30 days
Where possible, IntervalZero will notify the reporting entity when the process is concluded.
Review, Ownership, and Maintenance
This CVD Policy:
- Is clearly attributable to IntervalZero
- Is owned and maintained by the IntervalZero Product Security Team (PSIRT)
- Is reviewed at least annually by the PSIRT owner together with relevant Engineering and Compliance representatives
- Is updated as necessary to reflect regulatory, technical, or organizational changes