CVD Policy compliant with the Cyber Resilience Act (CRA)

Coordinated Vulnerability Disclosure (CVD) Policy

TELZAS
Version 1.0 | Publication date: 9 September 2026

Introduction

TELZAS is committed to maintaining a high level of security across its products and services. This policy defines the process for reporting and handling security vulnerabilities in accordance with the requirements of the Cyber Resilience Act (EU) 2024/2847.

Scope of the Policy

This policy applies to all TELZAS-supported products containing digital elements, including software, firmware, and other digital components supplied and maintained by TELZAS.

Reporting Vulnerabilities

Vulnerability reports should be submitted to security@telzas.com.

Reports should contain sufficient information to enable the identification and analysis of the vulnerability, including, in particular, the product or component name, product version, description of the vulnerability, information enabling the vulnerability to be reproduced, and an assessment of its potential security impact.

For reports containing technical details of a vulnerability, the use of encrypted communication is recommended. The public PGP key is available at the address specified in the security.txt file.

Additional information regarding vulnerability reporting is published in the security.txt file available at: security.txt

Safe Harbor

TELZAS will not take legal action against individuals acting in good faith who responsibly report vulnerabilities without compromising data or disrupting the operation and availability of systems.

Vulnerability Handling Process

Receipt of a vulnerability report will be acknowledged within 3 business days. TELZAS will conduct a risk assessment, develop appropriate fixes, and provide the reporter with progress updates at least every 14 days.

Security Updates

Security fixes for supported products will be made available without undue delay and at no additional cost during the product support period.

Information Disclosure

Following the release of a security fix, TELZAS may publish security advisories containing a description of the vulnerability, the affected product versions, and recommended mitigation measures.

CRA Compliance

Where required by applicable regulations, TELZAS will fulfil its reporting obligations towards the relevant authorities, ENISA, and CSIRT teams.

Security Contact

E-mail: security@telzas.com

VULNERABILITY REPORTING POLICY IN ACCORDANCE WITH RFC 9116 (security.txt)

security.txt