Vulnerability Disclosure Policy
This Vulnerability Disclosure Policy ("Policy") describes how MiseCentral LLC ("MiseCentral," "we," "us," or "our") receives, classifies, remediates, and discloses security vulnerabilities affecting the Services. This Policy works together with the Responsible Disclosure Policy, which governs researcher conduct and reporting channels.
1. Purpose
1.1. MiseCentral is committed to identifying and remediating security vulnerabilities in the Services in a timely, risk-based manner to protect Customer Data, operational integrity, and platform availability.
1.2. This Policy establishes internal and external expectations for vulnerability intake, severity assessment, remediation timelines, and coordinated disclosure.
2. Scope
2.1. This Policy covers vulnerabilities in:
(a) MiseCentral-hosted application code, APIs, and administrative interfaces;
(b) MiseCentral-managed cloud infrastructure supporting the Services;
(c) MiseCentral authentication, authorization, Support Mode, and Partner Support Mode mechanisms; and
(d) MiseCentral-operated integration endpoints and Marketplace infrastructure where enabled.
2.2. Vulnerabilities in third-party Subprocessors, Connected Services, Customer-managed devices, or partner systems are addressed through vendor management, Customer governance, or partner coordination as appropriate, and may fall outside direct remediation by MiseCentral.
3. Vulnerability Intake Sources
3.1. MiseCentral receives vulnerability information through:
(a) external reports submitted under the Responsible Disclosure Policy;
(b) internal discovery through secure development, code review, automated scanning, and penetration testing;
(c) Subprocessor and vendor notifications;
(d) Customer or Partner reports through support or security channels; and
(e) threat intelligence and public advisory sources.
3.2. All intake channels route to MiseCentral's security function for triage and tracking.
4. Severity Classification
4.1. MiseCentral classifies validated vulnerabilities using an internal severity model informed by industry practice, considering exploitability, authentication requirements, data exposure potential, scope of impact, and effect on confidentiality, integrity, or availability of the Services or Customer Data.
4.2. Severity levels guide remediation priority:
(a) Critical — vulnerability reasonably permitting unauthorized access to Customer Data at scale, unauthenticated remote code execution on production systems, or widespread service compromise without meaningful mitigating controls.
(b) High — vulnerability permitting privileged unauthorized access, significant authentication bypass, or substantial data exposure under common configurations.
(c) Medium — vulnerability requiring specific conditions or authenticated access, with limited blast radius or meaningful compensating controls.
(d) Low — vulnerability with minimal practical impact, difficult exploitation, or defense-in-depth weakness without direct data exposure.
(e) Informational — observation that does not constitute an exploitable vulnerability but may inform hardening.
4.3. Severity assignments are re-evaluated as new information emerges.
5. Remediation Targets
5.1. Upon validation, MiseCentral targets remediation or implementation of compensating controls according to severity:
(a) Critical — begin containment immediately; target remediation or verified mitigation as rapidly as practicable.
(b) High — target remediation within commercially reasonable timeframes commensurate with risk.
(c) Medium and Low — schedule remediation according to engineering capacity and risk priority.
(d) Informational — address as part of continuous improvement unless elevated by context.
5.2. Targets are goals, not guarantees. Complex vulnerabilities, dependency on third parties, or required Customer configuration changes may extend timelines. MiseCentral will communicate material delays to affected parties where appropriate.
5.3. Emergency changes follow MiseCentral's change management procedures with expedited review appropriate to incident risk.
6. Customer Notification
6.1. Where a validated vulnerability materially affects the security of Customer Data or requires Customer action, MiseCentral will notify affected Customers through support channels, in-product notices, or email in accordance with the Agreement, DPA, and applicable law.
6.2. Notifications will describe, to the extent known: the nature of the vulnerability; affected components; remediation or mitigation status; recommended Customer actions, if any; and contact information for follow-up.
6.3. MiseCentral will not disclose Customer-specific exploit details in public advisories.
7. Coordinated Disclosure
7.1. MiseCentral coordinates public disclosure of material vulnerabilities after remediation or verified mitigation is available, unless earlier disclosure is required by law or necessary to protect Customers.
7.2. External reporters who comply with the Responsible Disclosure Policy may receive advance notice of planned disclosure timing.
7.3. Public advisories are published on MiseCentral's security communications channels and may include CVE identifiers where applicable.
7.4. MiseCentral credits external reporters in public advisories when the reporter consents and MiseCentral determines credit is appropriate.
8. Vulnerability Management Program
8.1. Dependency Management. MiseCentral monitors third-party dependencies for known vulnerabilities and applies updates according to the Secure Development Policy.
8.2. Penetration Testing. MiseCentral conducts penetration testing and security assessments on a risk-based schedule. Results feed remediation backlogs.
8.3. Regression Prevention. Remediated vulnerabilities are covered by tests or monitoring where practicable to prevent recurrence.
8.4. Support Mode Hardening. Vulnerabilities affecting Support Mode or Partner Support Mode receive elevated priority due to privileged assistance context.
9. Exceptions and Risk Acceptance
9.1. Where immediate remediation is infeasible, MiseCentral may implement compensating controls and document risk acceptance with appropriate internal approval until permanent remediation is complete.
9.2. Risk acceptance records include justification, owner, review date, and affected systems.
10. Metrics and Review
10.1. MiseCentral tracks vulnerability intake volume, time-to-remediate by severity, and recurring vulnerability classes to inform security investment.
10.2. This Policy is reviewed at least annually and after material security events.
11. Contact
Vulnerability reports and disclosure inquiries:
MiseCentral LLC Attn: Security — Vulnerability Disclosure 8 The Green, Suite A Dover, DE 19901 United States security@misecentral.com
Version history
| Version | Effective | Summary |
|---|---|---|
| 1.0 | August 1, 2026 | Initial publication of the Legal Library (LEGAL-01). |
Previous versions remain available for reference and are never overwritten.