Security Policy for CppModel

1. Our Commitment

Control Edge AB ("we," "us," "our") takes the security of CppModel seriously. We welcome reports from security researchers who discover vulnerabilities in our products and services, and we are committed to working with you to understand and resolve issues quickly.

2. Scope

This policy applies to:

Third-party services we rely on (for example our payment processor, scheduling tool, or identity provider) are out of scope. Please report vulnerabilities in those services directly to the respective vendor.

3. How to Report a Vulnerability

Email [email protected] with:

Please do not include real customer data in your report. If you believe your finding affects customer data, describe the issue without including the data itself.

4. Rules for Testing

When researching a potential vulnerability, please:

5. What You Can Expect From Us

6. Coordinated Disclosure

We ask that you give us 90 days from your initial report to investigate and remediate the issue before making any public disclosure, and that we coordinate with you on the timing and content of any public writeup. If a fix requires more time, we will communicate this and work with you on a mutually agreeable timeline.

7. Safe Harbor

We will not pursue legal action against researchers who discover and report vulnerabilities in good faith, in accordance with this policy, and who provide us a reasonable opportunity to investigate and remediate the issue before any public disclosure. This safe harbor does not extend to testing that violates the rules described in Section 4, or to actions that violate applicable law.

8. Changes to This Policy

We may update this Security Policy from time to time. We will post the updated policy on our website.

9. Contact Information

If you have any questions about this Security Policy, please contact us at [email protected].