Vulnerability Disclosure Policy

Screenly

Vulnerability Disclosure Policy

Product: Screenly

Manufacturer: Screenly, Inc

Version: 1.0

Date: 2026-05-20


1. Introduction

Screenly, Inc is committed to the security of Screenly and welcomes reports from security researchers and the general public to help improve our security posture. This policy describes how to report vulnerabilities and what to expect from us.

2. Scope

This vulnerability disclosure policy applies to Screenly.

3. How to Report a Vulnerability

Email: [email protected]

When reporting, please include:

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact assessment
  • Any suggested remediation

4. Response Timeline

  • Acknowledgment: [To be determined]
  • Status Update: Within 14 days of acknowledgment
  • Resolution Target: Within 90 days of validated report

5. Safe Harbor

Screenly, Inc will not take legal action against individuals who:

  • Make a good faith effort to comply with this policy
  • Report vulnerabilities without exploiting them beyond what is necessary to confirm the vulnerability
  • Do not violate privacy, destroy data, or disrupt services

6. Coordinated Disclosure

We ask reporters to:

  • Allow reasonable time for remediation before public disclosure
  • Coordinate disclosure timing with us
  • Avoid accessing or modifying data beyond what is necessary

7. Recognition

We acknowledge security researchers who report valid vulnerabilities in accordance with this policy.


This policy aligns with CRA Annex I, Part II, Sections 5-6 requirements for coordinated vulnerability disclosure.