Cenitia compliance workflow

How it works →

Practical template

Hardware vulnerability disclosure policy template

Use this template with your own product details and evidence. Copy the text into your document to complete the fields and add rows as needed.

Replace every placeholder and obtain operational, security and legal review before publishing. This template grants no permission to test any system.

  • Policy owner/version: [fill in]
  • Covered products/versions/services: [fill in]
  • Reporting channel: [fill in]
  • Secure evidence transfer arrangement: [fill in]
  • Acknowledgement target and backup owner: [fill in]
  • Escalation channel: [fill in]

Please include product model, firmware version, reproduction steps, observed impact and non-sensitive logs. Remove credentials and personal information; arrange sensitive transfers with the response team.

Permitted research systems and activity, after approval: [fill in]. Excluded activity and customer systems: [fill in]. Legal assurance approved by counsel, if any: [fill in]. Bounty or credit arrangements: [fill in].

Our coordination process: acknowledge; triage; provide the next update date; agree disclosure where appropriate; communicate affected and corrected releases. Internal regulatory reporting assessment owner: [fill in]. Do not promise confidentiality or disclosure delays beyond what the actual process supports.

Example security.txt (reserved domain; does not receive reports):

Contact: mailto:security@example.com
Expires: 2027-01-01T00:00:00Z
Preferred-Languages: en
Canonical: https://example.com/.well-known/security.txt
Policy: https://example.com/security-policy

Prelaunch exercise evidence: external message received [fill in]; backup access [fill in]; escalation [fill in]; renewal owner [fill in]; reviewer/date [fill in].