StateNull — Coordinated Vulnerability Disclosure Policy ======================================================= Last updated: 2026-07-05 We welcome and reward good-faith security research. This policy tells you how to report a vulnerability, what you may and may not do, and how quickly we will respond. HOW TO REPORT Email media.supply@statenull.com with subject 'StateNull WEB | Security | '. Encrypt sensitive details if you can (PGP key on request). Include: affected component/URL, steps to reproduce, impact, and any PoC. One issue per report. OUR COMMITMENT (targets) - Acknowledgement of your report: within 2 business days - Triage + initial severity assessment: within 5 business days - Progress updates: at least every 10 business days until resolved - Coordinated public disclosure: by mutual agreement, default 90 days after triage We will credit you (if you wish) once a fix is released. SAFE HARBOR We will not pursue or support legal action against research that follows this policy and: - stays within the SCOPE below, - does not access, modify, or exfiltrate data that is not your own test data, - does not degrade service (no DoS, no automated high-volume scanning), - gives us reasonable time to remediate before any public disclosure. IN SCOPE statenull.com and app.statenull.com (control plane, verify portal, admin center), the StateNull-SecoM mobile app, and the published container images. OUT OF SCOPE - Denial-of-service, volumetric or brute-force testing. - Social engineering, physical attacks, or attacks on our staff/vendors. - Findings that require a rooted/jailbroken device or a compromised OS. - Reports from automated scanners without a demonstrated, exploitable impact. - Third-party services we do not operate. Regulatory note: for products in the EU, StateNull follows the coordinated-disclosure and incident-reporting expectations of the Cyber Resilience Act (CRA) and NIS2. Actively exploited vulnerabilities are handled on the accelerated timeline described in our incident-response process.