Policy
Coordinated disclosure policy
CipherCue operates a continuous external observation programme. When an observation indicates a catalogued security issue against an organisation's publicly-exposed software, we attempt to notify that organisation before exposing the observation on any CipherCue customer surface.
48-hour silent window. Every new pre-disclosure observation is held silent for 48 hours while we attempt responsible disclosure to the affected organisation.
Scope
This policy covers observations CipherCue generates itself — principally KEV matches against observed fingerprints and suspected-incident patterns (e.g. emergency certificate rotation, unplanned DNS authority change). It does not cover public authority records (e.g. state AG breach notifications, SEC 8-K): those are already public.
Silent window
When a new pre-disclosure observation is recorded:
- A
DisclosureAttemptrecord is created. - CipherCue attempts to contact the target (see "Channels" below).
- 48 hours after the attempt — regardless of whether a response was received — the observation is released to customer-facing surfaces.
- If the target acknowledges and requests an extended window, we honour a single 14-day extension on written request.
Channels
In priority order:
security.txtcontact (RFC 9116).- WHOIS abuse contact, where resolvable.
security@{domain}as a fallback.
Standards alignment
- CERT/CC coordinated disclosure norms.
- ISO/IEC 29147 — Vulnerability disclosure.
- FIRST.org disclosure practice guidelines.
- RFC 9116 — security.txt.
Contact for coordinated disclosure
security@ciphercue.com is the single address for coordinated disclosure matters, including requests for extension and notices of remediation.
v1.0 — 2026-06-12 — Initial publication. 48-hour silent window, three-channel contact resolution.