Vulnerability Disclosure Policy
Vulnerability Disclosure Policy
Organization: Adaptive NV
Status: Active | Effective Date: [01.08.2026] | Last Updated: [05.08.2026]
Adaptive NV is committed to ensuring the security and resilience of our digital products in alignment with the EU Cyber Resilience Act (CRA) and applicable Belgian cybersecurity regulations. This policy outlines how security researchers and users can report vulnerabilities found in our software ecosystem and defines our remediation standards.
Scope
This policy covers the Adaptive NV core software platform and customer-specific implementations.
Out of Scope: Third-party services not directly managed by Adaptive NV and physical security of offices or data centers.
Report a Vulnerability
If you discover a security vulnerability, please report it to our security team.
Primary Contact: Mikhail Snegirev
Encrypted Communication: Send reports to so@pearlchain.atlassian.net
Subject Line: "Vulnerability Disclosure: [Short Description]"
Required Information:
Description of the vulnerability and impact.
Detailed steps to reproduce the issue (PoC).
Specific software version(s) affected.
Our Management Process
We follow a standardized process to ensure timely remediation and transparency:
Acknowledgment (Within 2 Business Days): Confirmation of receipt and assignment of a tracking ticket.
Initial Assessment (Within 10 Business Days): Verification of the vulnerability and categorization of severity.
Remediation (Priority-based): Development and validation of a patch or mitigation strategy.
Notification (Post-Fix): Reporting back to the researcher on the final resolution.
Regulatory Compliance (EU CRA)
Adaptive NV maintains strict protocols for notifying supervisory authorities of security incidents via the ENISA Single Reporting Platform (SRP)
Actively Exploited Vulnerabilities
24-Hour Warning: Immediate notification regarding potential unlawful acts or cross-border impact.
72-Hour Notification: Comprehensive update with technical details and risk assessment.
14-Day Final Report: Post-remediation details including root cause analysis and update instructions.
Severe Security Incidents
Any incident impacting digital product integrity or availability is reported via the ENISA SRP within 24 hours of detection.
Security Updates
Once a vulnerability is remediated:
Version Tracking: Updates are uniquely identified across our customer base.
JET Logging: Installation is recorded in the Technical Event Log (JET).
Integrity: Updates are digitally hashed/fingerprinted for authenticity.
Safe Harbor
Adaptive NV will not pursue legal action against individuals who submit reports in good faith, provided they:
Comply with this policy and applicable laws.
Avoid data destruction or service interruption.
Provide a reasonable time for us to remediate the issue.
Coordinated Vulnerability Disclosure (CVD)
We operate under a Coordinated Vulnerability Disclosure framework to ensure ecosystem safety.
Coordination: Please do not disclose vulnerability details or PoCs without prior coordination with our team.
Timeline: We target a 90-day window for mitigation. We will collaborate on a mutually acceptable public disclosure date once all active clients are patched