Coordinated Vulnerability Disclosure (CVD) Policy

At Stardust Systems Inc, we take the security and resilience of our products and services seriously. In alignment with the EU Cyber Resilience Act (CRA), we maintain this dedicated single point of contact to welcome feedback from security researchers and the broader community.

If you believe you have discovered a security vulnerability, we encourage you to report it to us safely through our coordinated disclosure process outlined below.

1. How to Report a Vulnerability

Please submit all vulnerability reports directly to our security team.

To protect sensitive data, we request that you encrypt all submission details using our Public PGP Key.

Our Public PGP Key

Please download the key file directly from here

2. What to Include in Your Report

To help us triage and resolve the issue quickly, please copy and paste the template questionnaire below into your email. This ensures our team has all the necessary details to process your report efficiently:

--- VULNERABILITY REPORT TEMPLATE ---

CONTACT DETAILS
- Reporter Name/Alias: 
- Website/Social (Optional for credit): 

VULNERABILITY DETAILS
- Vulnerability Type (e.g., SQLi, XSS, Info Disclosure): 
- Affected URL / Component: 
- Severity Estimate (Low / Medium / High / Critical): 

PROOF OF CONCEPT (PoC)
- Detailed Step-by-Step Instructions to Reproduce: 
  1. 
  2. 
  3. 
- Impact (What can an attacker achieve with this?): 

REMEDIATION SUGGESTIONS (Optional)
- Recommended fix or mitigation steps:

3. Our Commitment to You

When you report a vulnerability following this policy, we commit to the following timelines:

  • Acknowledgment: We will acknowledge receipt of your report within 3 business days.
  • Status Updates: We will provide timely status updates at least once every 7 business days while the issue is being investigated and resolved.
  • Remediation: We will work diligently to validate and fix the vulnerability based on its severity level.
  • Credit: With your permission, we will gladly recognize your contribution once the vulnerability has been resolved and publicly disclosed.

4. Our Commitment & Regulatory Compliance

When you report a vulnerability following this policy, we commit to the following timelines for you:

  • Acknowledgment: We will acknowledge receipt of your report within 3 business days.
  • Status Updates: We will provide timely status updates to you at least once every 7 business days while the issue is being investigated and resolved.

CRA Regulatory Notification: In strict compliance with Article 14 of the EU Cyber Resilience Act, if an investigation confirms that a validated vulnerability is being actively exploited in the wild, our organization will independently notify the European Union Agency for Cybersecurity (ENISA) and relevant Computer Security Incident Response Teams (CSIRTs) within the mandated 24-hour early warning and 72-hour notification windows.

5. Ground Rules & Safe Harbor

We support responsible security research. If you make a good-faith effort to comply with this policy during your investigation, we will not pursue legal action against you.

We ask that you:

  • Avoid violating privacy, destroying data, or interrupting our services (such as DoS/DDoS attacks).
  • Give us a reasonable amount of time to remediate the issue before publishing or sharing any information publicly.
  • Do not interact with or compromise account data belonging to other users.

Thank you for helping us keep our products and users secure.