Navitec Systems Coordinated Vulnerability Disclosure (CVD) Policy

Last updated: 2026‑09‑07

1. Purpose

This Coordinated Vulnerability Disclosure (CVD) policy defines how security vulnerabilities in Navitec Systems’ products and services can be responsibly reported, assessed, remediated, and disclosed. This policy fulfils the obligation set out in Annex I, Part II, point (5) of Regulation (EU) 2024/2847 (Cyber Resilience Act).

2. Scope

This policy applies to:

  • All Navitec software products and related services (web services and APIs).
  • All Navitec deployments (on-premise and cloud-based).
  • All Navitec hardware-integrated software components.
  • Vulnerabilities discovered by internal teams or external parties.
3. Principles
  • Good‑faith collaboration: We welcome responsible security research.
  • User protection first: Vulnerabilities are remediated before disclosure.
  • Transparency: Clear communication throughout the disclosure lifecycle.
  • Timeliness: Vulnerabilities are handled without undue delay.
4. How to Report a Vulnerability

Security issues should be reported as soon as possible by individuals or organizations.

4.1 Direct report

Report security issues to Navitec’s single point of contact for vulnerability reporting:

  • Email: security AT navitecsystems.com

This is Navitec’s designated channel for security reports. The general support channels — support portal, support email and support phone line — are not: an issue sent there will be routed onward, but reporting directly to security AT navitecsystems.com reaches Navitec’s security teams without delay.

4.2 Anonymous report

If you prefer to report anonymously, you can use:

  • National cybersecurity authority: Use your country’s official cybersecurity reporting channel.
  • EU Single Reporting Platform: Link will be added once it is launched.

Reports should include (if available):

  • Product and version.
  • Description of the vulnerability.
  • Steps to reproduce.
  • Any supporting materials (e.g., screenshots, logs, proof-of-concept code).
  • Potential impact.
  • Reporter contact information (optional for anonymous reporting).
5. Researcher Commitments

Researchers must:

  • Avoid accessing or modifying user data.
  • Avoid service disruption.
  • Not publicly disclose vulnerabilities.
  • Comply with applicable laws.
6. Navitec Commitments

Navitec will publicly disclose vulnerabilities only after a security update has been made available.

We commit to reporters/researchers to:

  • Work with reporters to validate and remediate the vulnerability.
  • Acknowledge valid vulnerability reports within 5 business days.

We commit to authorities in case of an actively exploited vulnerability (Article 14(1-2)) to:

  • Provide an early warning notification via the single reporting platform within 24 hours of becoming aware.
  • Provide a vulnerability notification via the single reporting platform within 72 hours of becoming aware.
  • Provide a final report no later than 14 days after a corrective or mitigating measure is available.

We commit to authorities in case of a severe incident having an impact on the security of a product with digital elements (Article 14(3-4)) to:

  • Provide an early warning notification via the single reporting platform within 24 hours of becoming aware.
  • Provide an incident notification via the single reporting platform within 72 hours of becoming aware.
  • Provide a final report within one month after the submission of the incident notification.

We commit to our customers to:

  • Investigate and validate the vulnerability.
  • Provide a fix or mitigation for validated vulnerabilities without undue delay, based on severity.
  • Inform affected customers about the vulnerability and provide clear guidance on mitigation steps and protective measures.
7. Public Disclosure of Fixed Vulnerabilities

Once a security update is available, Navitec will publicly disclose information about the fixed vulnerability. The disclosure will include:

  • A description of the vulnerability.
  • Information identifying the affected product(s) and version(s).
  • The impact and severity of the vulnerability.
  • Clear and accessible remediation guidance for users.
7.1 Disclosure channel

Public disclosures will be published on the Navitec GitHub Security Advisories page.

7.2 Delayed disclosure

In duly justified cases, where the security risks of immediate publication outweigh the security benefits, Navitec may delay making public information regarding a fixed vulnerability until users have been given the possibility to apply the relevant patch.

8. Legal Safe Harbor

If you conduct security research in good faith and in compliance with this policy, Navitec commits to:

  • Not initiating criminal or civil legal action against you for your research activities.
  • Not referring your activities to law enforcement, provided they are conducted in accordance with this policy.
  • Working with you to understand and resolve the issue before any public disclosure.
  • Not imposing any additional obligations on you beyond what is required by this policy as a result of your voluntary report.

Good faith means:

  • Acting with no malicious intent, for purposes of testing, investigation, correction, or disclosure to promote the security or safety of users and systems.
  • Making a reasonable effort to avoid privacy violations, data destruction, and service disruption.
  • Only interacting with accounts you own or have explicit permission to test.
  • Stopping testing and reporting immediately if you encounter user data.

This safe harbor is consistent with the principles set out in Recital 75 and Recital 76 of Regulation (EU) 2024/2847 (Cyber Resilience Act), which encourage Member States to adopt guidelines regarding the non-prosecution of information security researchers and an exemption from civil liability for their activities.