Vulnerability Disclosure Policy

Vulnerability Disclosure Policy

Cyber Resilience Act VDP

1 Purpose

The purpose of this policy is to establish a transparent and secure process for reporting vulnerabilities in digital products or solutions offered by Codelab sp. z o.o. (hereinafter: “the Company”), in a way that supports user security and compliance with the Cyber Resilience Act (CRA) and the General Data Protection Resolution (GDPR).

2 Scope

The policy includes:

  • products and solutions offered by the Company,
  • digital components that are part of systems delivered to customers,
  • the process of managing vulnerability reports from researchers, customers, or third parties.

3 Vulnerability reporting

We encourage everyone to report any vulnerabilities one notice through one of the following channels:

When reporting incident and/or vulnerability, please provide:

  • description of the vulnerability and/or incident, and its potential effects,
  • steps to reproduce it (if possible)
  • screenshots, logs or PoC code (if available),
  • contact information (anonymous reports are also accepted, the Company does not anonymize data or ensure anonymity).

Note: Please send personal user data (e.g., logs, screenshots) only when necessary for vulnerability analysis.

4 Principles of cooperation

We ask security researchers to:

  • act in accordance with the law and in good faith,
  • refrain from disclosing vulnerabilities to the public before the completion of the remediation process (so-called responsible disclosure),
  • Avoid breaches of user data and service interruptions,
  • Always comply with applicable data protection laws and refrain from violating the privacy of users, employees, contractors, systems, or services of the Company. In particular, it is strictly prohibited to share, redistribute, or store any data obtained from systems or services.
  • securely delete any data obtained during security research as soon as it is no longer required, or within one (1) month after the reported vulnerability has been remediated — whichever occurs first (or in line with any applicable data protection regulations).

Please refrain from doing the following:

  • Accessing excessive, irrelevant, or sensitive data beyond what is necessary for demonstrating the vulnerability.
  • Modifying data stored in the Company’s systems or services.
  • Using aggressive, invasive, or destructive tools to scan for vulnerabilities.
  • Performing or reporting any form of denial-of-service (DoS) attack, such as overwhelming services with traffic.

Disrupting, impairing, or intentionally interfering with the normal operation of Company systems or services.

Vulnerability reports are processed free of charge and do not entail any form of remuneration or reward.

The Company reserves the right to report any activities deemed illegal to the appropriate authorities.

5 Vulnerability handling process

StageActionExpected closure date
1. ConfirmationAcknowledgment of receipt of the requestup to 7 working days
2. VerificationTechnical analysis and risk classificationup to 30 working days
3. OperationPreparation and implementation of the solutiondepending on the criticality
4. CommunicationInforming the reporter and usersOnce the analysis and repair is complete
5. Notification to the appropriate CSIRT and ENISA(if applicable) reporting an incident or vulnerabilityup to 24 hours from the detection of a vulnerability actively exploited

Reported vulnerabilities will be handled internally in accordance with Codelab Incident Management process.

6 Protection of the whistleblower data

The data of the reporting persons is processed in accordance with the principles of the GDPR and used only for contact related to the report and ensuring system security. Anonymous reports are also accepted; the Company does not anonymize data or ensure anonymity. The controller of personal data is Codelab sp. z o.o. ul. Zbożowa 4, 70-653 Szczecin. Detailed information on data processing is provided in the information clause attached as Appendix 1 to this procedure.

7 Contact

If you have any questions about this policy, please contact us at: svd@codelab.eu

Date of adoption and update

  • Effective Date: 24-04-2026
  • Subsequent review: every 12 months


 

Appendix 1

GDPR information clause for vulnerability reporters

In accordance with Article 13 and 14 of the GDPR, we hereby inform you that:

  1. Data Controller is Codelab sp. z o.o. ul. Zbożowa 4, 70-653 Szczecin, email: privacy@codelab.eu.
  2. Purpose of data processing is to handle vulnerability reports in our products and systems, as well as possible contact with people making reports.
  3. Legal basis for processing is:
  4. Article 6(1)© of the GDPR (fulfilment of a legal obligation incumbent on the Controller, resulting from cybersecurity regulations, including the Cyber Resilience Act) and
  5. Article 6(1)(f) of the GDPR (legitimate interest of the Controller in ensuring system security) - in the case of processing personal data of persons to whom the report relates
  6. Processed data categories are first name, last name, email address, and other data provided voluntarily by the reporting person.
  7. Data recipients are authorized employees of the Controller and entities providing IT infrastructure services.
  8. The data will be stored for no longer than 12 months from the end of the report handling process.
  9. You have the right to: access to data, rectification, erasure, restriction of processing, objection.
  10. You have the right to lodge a complaint with the President of the Personal Data Protection Office.
  11. Personal data may be obtained directly from the reporting person or indirectly from materials submitted as part of the vulnerability report.
  12. Providing personal data is voluntary but may be necessary to respond to your enquiry.