All Policies

Vulnerability Management Policy

Effective Date: April 23, 2026

1. Purpose

This policy establishes procedures for identifying, assessing, and remediating security vulnerabilities in VaultKeeper systems within defined service level agreements (SLAs).

2. Vulnerability Identification

Vulnerabilities are identified through:

3. Severity Classification

SeverityCVSS ScoreDescription
Critical9.0 - 10.0Actively exploitable, direct access to consumer data, remote code execution
High7.0 - 8.9Significant risk, potential data exposure, privilege escalation
Medium4.0 - 6.9Limited risk, requires specific conditions to exploit
Low0.1 - 3.9Minimal risk, informational findings

4. Patching SLAs

SeverityRemediation DeadlineActions
Critical24 hoursImmediate patch or mitigation. Consider taking affected service offline if needed.
High7 daysPrioritize patch deployment. Apply compensating controls if patch is delayed.
Medium30 daysSchedule patch in next maintenance cycle.
Low90 daysAddress in regular development cycle.

5. Remediation Process

6. Managed Service Vulnerabilities

For vulnerabilities in managed services (Firebase, Cloudflare Workers), remediation is handled by the service provider. Our responsibility is to:

7. Responsible Disclosure

If a security vulnerability is discovered in VaultKeeper by an external party, we encourage responsible disclosure via the contact information in our Privacy Policy.

8. Policy Review

This policy is reviewed at least annually or after any significant security incident.