Vulnerability Disclosure Policy
Screenly
Vulnerability Disclosure Policy
Product: Screenly
Manufacturer: Screenly, Inc
Version: 1.0
Date: 2026-05-20
1. Introduction
Screenly, Inc is committed to the security of Screenly and welcomes reports from security researchers and the general public to help improve our security posture. This policy describes how to report vulnerabilities and what to expect from us.
2. Scope
This vulnerability disclosure policy applies to Screenly.
3. How to Report a Vulnerability
Email: [email protected]
When reporting, please include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact assessment
- Any suggested remediation
4. Response Timeline
- Acknowledgment: [To be determined]
- Status Update: Within 14 days of acknowledgment
- Resolution Target: Within 90 days of validated report
5. Safe Harbor
Screenly, Inc will not take legal action against individuals who:
- Make a good faith effort to comply with this policy
- Report vulnerabilities without exploiting them beyond what is necessary to confirm the vulnerability
- Do not violate privacy, destroy data, or disrupt services
6. Coordinated Disclosure
We ask reporters to:
- Allow reasonable time for remediation before public disclosure
- Coordinate disclosure timing with us
- Avoid accessing or modifying data beyond what is necessary
7. Recognition
We acknowledge security researchers who report valid vulnerabilities in accordance with this policy.
This policy aligns with CRA Annex I, Part II, Sections 5-6 requirements for coordinated vulnerability disclosure.