Coordinated Vulnerability Disclosure (CVD) Policy
Axiomtek follows Coordinated Vulnerability Disclosure principles and is committed to handling reported vulnerabilities in a responsible and transparent manner. Our disclosure activities are coordinated with reporters and aligned with applicable requirements under the EU Cyber Resilience Act (CRA).
How to Report a Vulnerability
For the secure submission of sensitive information, please use PGP public-key encryption.
Safe Harbor: Axiomtek will not initiate legal action against security researchers who conduct vulnerability research in good faith and comply with this policy.
Reporting Obligations
As required by the EU Cyber Resilience Act (effective 11 September 2026), Axiomtek reports actively exploited vulnerabilities and severe incidents to ENISA via the Single Reporting Platform:
Early Warning
Early warning submitted to ENISA in accordance with CRA reporting requirements upon awareness of an actively exploited vulnerability or severe incident.
72H Notification
Formal notification providing further technical assessments, vulnerability characteristics, and initial remediation steps.
Final Report
Detailed closure report submitted in accordance with CRA requirements, specifying corrective measures and resolution details.