Introduction

tenfold is committed to ensuring the security and privacy of our digital products. This Coordinated Vulnerability Disclosure (CVD) policy outlines our process for receiving, investigating, and resolving reported security vulnerabilities.

This policy is implemented in accordance with Regulation (EU) 2024/2847 (Cyber Resilience Act – CRA), Annex I, Part II, and forms an integral part of our product lifecycle vulnerability management process.

Scope

This policy applies to:

  • All applications published by tenfold.
  • Web content hosted at tenfold-security.com.

Out of Scope:

  • Issues that affect only earlier, superseded software versions.
  • Vulnerabilities in third-party products, services, or platforms not integrated into tenfold products. These must be reported directly to the respective manufacturer or vendor.
  • Social engineering of tenfold employees or customers.
  • Physical attacks on our facilities or devices.
  • Denial-of-Service (DoS/DDoS) attacks.
  • Automated scanner reports lacking demonstrated, exploitable impact.

Reporting a Vulnerability

If you discover a security vulnerability in a tenfold product, please submit your report to: vulnerability@tenfold-security.com

We accept reports in English and German. For standardized security data, you can also consult our security.txt file (RFC 9116).

To help us process your report efficiently, please include:

  • Affected product(s) and specific version number(s).
  • Clear description of the vulnerability.
  • Detailed, step-by-step reproduction instructions (or proof-of-concept).
  • Impact assessment across confidentiality, integrity, and availability.
  • Your contact details for follow-up communication.
  • Suggested remediation or fix (optional).

Procedural Steps and Timeline

Upon receiving your report, we will take all necessary steps to investigate and resolve the issue in a swift and transparent manner.

While we cannot commit to a fixed timeline for every patch, we are committed to keeping you informed at each step of the process.

To maintain mutual trust and ensure our customers have adequate time to deploy updates, we ask that you keep all communications regarding the vulnerability confidential until a fix is released.

Once a fix is available, we will document the vulnerability in the release notes of the corresponding update and credit the reporter(s), unless you request to remain anonymous.

Notification to ENISA and CSIRTs

In accordance with the Cyber Resilience Act (CRA), if we determine that a vulnerability is being actively exploited or presents a severe security risk to our users, tenfold will notify the European Union Agency for Cybersecurity (ENISA) and the designated national Computer Security Incident Response Teams (CSIRTs) via the Single Reporting Platform (SRP) within statutory deadlines.

Safe Harbor

tenfold will not pursue legal action against researchers who discover and report vulnerabilities in good faith and in compliance with this policy.

To remain covered under this safe harbor, you must:

  • Act in good faith and strictly adhere to this CVD policy.
  • Avoid accessing, modifying, exfiltrating, or deleting user data.
  • Avoid service disruptions, degradation, or intentional harm to customers or infrastructure.
  • Report discovered vulnerabilities promptly and allow reasonable time for remediation prior to any public disclosure.

Note: This safe harbor applies to computer access laws and incidental access to personal data during bona fide security research. It does not cover malicious activity, service abuse, or deliberate harm.