Responsible Disclosure Welcome

Security & Vulnerability Disclosure

Found a security issue in our website or the Crosswalk app? Here is how to report it — and what you can expect from us in return.

/.well-known/security.txtLast updated: 30 September 2026

We welcome responsible reports

We build compliance tooling, so we hold ourselves to the coordinated vulnerability disclosure practices we advocate. If you have found a security issue, please tell us before sharing it publicly, and we will work with you to fix it.

1

Reporting a Vulnerability

Report by email

Start here

Send your findings to our security contact. The more detail you give, the faster we can validate and fix the issue.

  • Email [email protected]
  • Describe the issue and its potential impact
  • Include clear steps to reproduce (and a minimal proof-of-concept if you have one)
  • Note the affected URL, page or component (e.g. the Crosswalk app at /crosswalk)
  • Tell us how you would like to be credited — or ask to stay anonymous

What happens next

Within 3 business days

You will not be left in the dark. We keep you informed at every step.

  • We acknowledge your report within 3 business days
  • We validate and triage the issue, and may ask for clarification
  • We keep you updated on remediation progress
  • We agree a coordinated disclosure timeline with you
2

Scope

In scope

Welcome

Assets we operate and want to hear about.

  • The website eu-cyber-laws.com and its subdomains
  • The Crosswalk compliance app served at eu-cyber-laws.com/crosswalk
  • Our contact/email handling (the Cloudflare email worker)

Out of scope

Please avoid

Reports of the following are unlikely to be actionable.

  • Third-party services and platforms we do not control
  • Volumetric denial-of-service (DoS/DDoS), spam or resource-exhaustion testing
  • Automated scanner output without a demonstrated, working proof-of-concept
  • Social engineering of our staff, partners or users; physical attacks
  • Best-practice suggestions with no concrete security impact (e.g. missing headers alone)
3

Coordinated Disclosure

Our commitment to you

Our promise

We practise coordinated vulnerability disclosure — the same responsible approach the EU Cyber Resilience Act expects of manufacturers.

  • We investigate every good-faith report and confirm whether it is valid
  • We remediate confirmed issues as quickly as their severity warrants
  • We coordinate public disclosure with you once a fix is available (typically within 90 days)
  • Our own reporting duties under the Cyber Resilience Act run on their own clock and are never delayed by coordination with a reporter: for an actively exploited vulnerability, an early warning to the CSIRT within 24 hours of becoming aware, a notification within 72 hours and a final report within 14 days (Art. 14)
  • Every fixed vulnerability is published on the security advisories page, with the affected versions and the fix
  • The software bill of materials of the current Crosswalk release, the VEX statements of its vulnerability check and the release record are published at /security/crosswalk/ (sbom.cdx.json, vex.cdx.json, release.json), readable worldwide
  • Security updates are provided free of charge for the whole support period, which runs until at least 15 September 2031. Only the latest version of Crosswalk receives them: the app checks for a new version itself, installs it and asks for a restart, so a fix reaches every running installation at its next start
  • We are happy to credit you for the discovery if you wish

What we ask of you

Please

A little cooperation keeps users safe while we fix the issue.

  • Give us a reasonable opportunity to resolve the issue before disclosing it publicly
  • Do not disclose details to third parties until we have published a fix or agreed a date
  • Send one clear report per issue so nothing gets lost
4

Safe Harbour & Rules of Engagement

Safe harbour for good-faith research

Good faith

If you make a good-faith effort to follow this policy, we will treat your research as authorised.

  • We will not pursue or support legal action for good-faith, in-scope research that respects these rules
  • Act in good faith, stay within scope, and avoid privacy violations and service disruption
  • If you encounter personal data, stop, do not store or share it, and tell us immediately

Rules of engagement

Boundaries

Test responsibly so users and their data stay protected.

  • Only test against your own accounts and data — never another user’s
  • Use the minimum interaction needed to demonstrate the issue
  • Do not run denial-of-service tests, send spam, or exfiltrate data beyond a minimal proof-of-concept
  • Do not access, modify or delete data that is not yours
5

Security Contact

PGP on request

Report a vulnerability or ask a question about this policy. If your report is sensitive, ask us and we will arrange an encrypted channel.

Email

[email protected]

Acknowledged within 3 business days

Machine-readable

/.well-known/security.txt

RFC 9116

Fixed vulnerabilities

/security/advisories

Every fixed vulnerability, with affected versions and the fix (CRA Annex I Part II(4))

Still Feeling Overwhelmed?

EU cybersecurity laws can be complex. Our free tools and guides work great for most people, but if you're dealing with something particularly challenging or have tight deadlines, we're here to help.