Coordinated Vulnerability Disclosure (CVD) Policy

1. Purpose

Percepio AB is committed to protecting the confidentiality, integrity, and availability of our products, services, and customer information. We recognise that independent researchers and customers can make an important contribution by reporting security issues responsibly. Our goal is to work with good-faith reporters to understand and resolve vulnerabilities, communicate appropriately with affected parties, and reduce risk for our customers and the wider community.

2. Scope

This policy applies to the following assets owned or operated by Percepio AB:

  • Our generally available products and services are listed at https://percepio.com/ and https://traceviewer.io/
  • Web applications, device software, container images, desktop applications and supporting infrastructure that we operate.
  • Official product documentation and integrations where the reported issue could affect Percepio AB or its customers.
  • To an applicable extent (due to the nature of open source development, Percepio can’t be held fully liable), the open source repositories maintained by Percepio at https://github.com/percepio.
  • Vulnerabilities identified in third-party components, libraries, or open-source software integrated into our products, in alignment with our Software Bill of Materials (SBOM) management.

If you are unsure whether an asset is in scope, please ask before testing. Customer-managed environments, third-party services, and systems operated by our suppliers are not automatically in scope.

3. How to report a vulnerability

Please report suspected vulnerabilities privately and as soon as reasonably possible through one of the following channels:

If available, use our published PGP key for sensitive information. Do not include real customer data, passwords, access tokens, or other secrets in a report. Redact or replace sensitive data with safe test values.

Recommended report contents

  • A clear description of the suspected vulnerability and the affected product, version, URL, or component.
  • Reproduction steps or a minimal proof of concept that demonstrates the issue without causing harm.
  • The potential impact, including what an attacker could access or change.
  • Any relevant logs, screenshots, request/response examples, or suggested remediation.
  • Your contact details and whether you would like to be credited if the issue is publicly disclosed.

4. Coordinated disclosure process

  1. Acknowledgement: We aim to acknowledge receipt within 3 business days.
  2. Triage: We will validate the report, assess severity and exploitability, identify affected versions or customers, and may request additional information.
  3. Remediation: We will assign an owner, develop and test a fix or mitigation, and determine whether customer notification is required.
  4. Coordination: We will keep the reporter informed where practical, particularly about the validation outcome and expected remediation timeline.
  5. Resolution: We will deploy or publish the fix or mitigation and close the report when the risk has been addressed or an agreed alternative is in place. Security updates and patches addressing verified vulnerabilities will be provided to all affected customers free of charge.
  6. Disclosure: Public disclosure should be coordinated with Percepio AB. We generally request up to 90 days from the initial report to remediate, subject to risk, active exploitation, complexity, and the needs of affected customers.
  7. Regulatory reporting (CRA): In accordance with the EU Cyber Resilience Act (CRA Article 14), if Percepio becomes aware of reliable evidence that a vulnerability is being actively exploited, or becomes aware of a severe incident having an impact on the security of our products, we will submit the required early warning stipulated by CRA without undue delay and within 24 hours, followed by the required subsequent notifications. We will also inform impacted users without undue delay as required by the CRA.

These are target timelines rather than guarantees. We may provide interim mitigations, advisories, or workarounds before a complete fix is available.

5. Severity and prioritisation

We use a risk-based assessment informed by exploitability, affected assets, data exposure, privileges required, customer impact, and whether the issue is being actively exploited. We may use CVSS as a reference but do not rely on a score alone.

Indicative severity Examples Target response
Critical Remote code execution, broad unauthorised access, or significant compromise of customer data or production systems. Immediate escalation; mitigation or remediation targeted as soon as practicable.
High Material customer data exposure, privilege escalation, authentication bypass, or significant loss of integrity. Prioritised remediation, normally targeted within 30 days where practicable.
Medium Meaningful but limited impact requiring specific conditions or lower privileges. Normally targeted within 90 days where practicable.
Low Limited-impact issues or weaknesses with difficult or unlikely exploitation. Addressed in the normal product or maintenance cycle.

6. Rules for good-faith testing

When testing in accordance with this policy, please:

  • Use only accounts and data you own or are explicitly authorised to use.
  • Limit testing to the minimum activity needed to demonstrate the issue.
  • Avoid accessing, modifying, deleting, downloading, or retaining other people’s data.
  • Do not disrupt services, degrade availability, send spam, or perform denial-of-service, stress, or load testing.
  • Do not use social engineering, phishing, physical intrusion, malware, persistence, or attacks against our employees, customers, or suppliers.
  • Stop testing and contact us immediately if you encounter sensitive data, production impact, or evidence of compromise.
  • Securely delete any data obtained during testing and confirm deletion if requested.

7. Out-of-scope reports and activities

The following are generally out of scope unless they demonstrate a realistic security impact:

  • Issues affecting unsupported, obsolete, or modified versions of our software.
  • Reports based only on automated scanner output without a reproducible impact.
  • Missing security headers or best-practice recommendations with no demonstrated exploitability.
  • Self-XSS, clickjacking on pages without sensitive actions, rate-limit observations without impact, and findings requiring unlikely user behaviour.
  • Spam, social engineering, denial-of-service, physical attacks, and vulnerabilities in third-party products or services.

We may close duplicate, incomplete, or non-security reports, and we may refer issues affecting a third party to the relevant provider.

8. Customer and partner reports

Customers and partners should report product vulnerabilities through the same channel. Do not test against another customer’s tenant or environment without explicit written authorisation. If the issue concerns a customer-managed deployment, please coordinate with the customer and provide Percepio AB enough technical detail to assess whether the product or our guidance is affected. We will handle customer information confidentially and will notify affected customers when we determine that notification is appropriate or required by contract or applicable law.

9. Safe harbour

We will not pursue or support legal action against a person who makes a good-faith effort to comply with this policy, avoids harm, respects privacy, and reports the issue promptly. This safe harbour applies only to activities within the scope of this policy and does not permit unlawful activity, access to systems or data without authorisation, or continued testing after we ask you to stop.

If a third party initiates legal action relating to activity that was consistent with this policy, we will take reasonable steps to explain that the activity was authorised under this policy. This statement does not waive any rights or obligations under applicable law.

10. Confidentiality and public disclosure

Please allow us reasonable time to investigate and remediate before publishing details. We will work with the reporter on the timing and content of any public advisory. We may publish a summary after remediation, normally without identifying the reporter unless they have agreed to be credited. When a vulnerability is publicly disclosed, Percepio AB will publish a security advisory containing: a clear description of the vulnerability and affected products/versions; the potential impact and severity (using CVSS as a reference); and clear remediation instructions, patches, or workarounds. This is in accordance with CRA Annex I, Part II requirements. We may ask for a longer coordination period where a fix is complex, exploitation is ongoing, or customers need additional time to apply a mitigation. We may support earlier disclosure where there is a clear public safety benefit and effective mitigations are available.

11. Communication and escalation

If you have not received an acknowledgement within 3 business days, please resend the report with the subject line “CVD escalation”. For an urgent issue involving active exploitation, widespread customer impact, or exposure of sensitive data, mark the report URGENT and include a safe contact method. We will communicate in English unless another arrangement is agreed. We cannot guarantee a particular outcome, reward, response time, or resolution for every report.

12. Recognition

We do not currently operate a bug bounty programme. At our discretion, we may thank contributors in a security acknowledgement or advisory, provided the reporter agrees and no sensitive information is disclosed. Any reward or recognition will be agreed separately and is not implied by this policy.

13. Policy maintenance

Percepio AB will review this policy at least annually and after significant changes to our products, services, or legal obligations. The current version will be published at https://percepio.com/security.

14. Contact

Security reports: security-report@percepio.com General security questions: security-question@percepio.com Company: Percepio AB

15. Regulatory compliance

This policy is designed to meet the vulnerability handling obligations of the EU Cyber Resilience Act (CRA), which applies to products with digital elements placed on the EU market. Key CRA obligations reflected in this policy include:

  • Active exploitation reporting (CRA Art. 14): Percepio AB will report actively exploited vulnerabilities within 24 hours of awareness, with a full notification within 72 hours.
  • Free security updates: Security fixes and patches are provided to customers free of charge.
  • Coordinated disclosure: Percepio AB follows a structured, coordinated disclosure process to minimise risk to customers and the wider ecosystem.
  • Third-party component management: Vulnerabilities in integrated third-party or open-source components are tracked and addressed in line with our SBOM practices.
  • Transparent advisories: Public security advisories include sufficient detail for customers to assess impact and apply remediation.

Percepio AB will update this policy as CRA implementing acts and guidance are published by the European Commission and ENISA.