CRA Security Policy
Vulnerability Disclosure Policy
Radiocrafts takes product security seriously and welcomes reports of potential security vulnerabilities in our products and services.
Reporting a Vulnerability
If you believe you have identified a security vulnerability, please send a report to:
Please include as much information as possible, such as:
- Product name and version
- Description of the vulnerability
- Steps to reproduce the issue
- Potential impact
- Your contact details if you would like feedback
- Our Commitment
When we receive a report, we will:
- Acknowledge receipt as soon as reasonably practical.
- Assess and investigate the reported issue.
- Take appropriate actions to mitigate or remediate confirmed vulnerabilities.
- Keep the reporter informed when appropriate.
- Responsible Disclosure
We ask that vulnerabilities are not publicly disclosed until Radiocrafts has had a reasonable opportunity to investigate and address the issue.
We also ask that testing is conducted in a manner that does not:
- Disrupt the availability of systems or services.
- Compromise data, privacy, or the security of other users.
- Violate applicable laws or agreements.
- We appreciate the efforts of security researchers and others who help improve the security of our products.
Radiocrafts supports coordinated vulnerability disclosure and will work with reporters to agree on an appropriate disclosure timeline.