Skip to content
MiseCentral
Platform Overview Work Intelligence Product Tour Technology Profile Integrations Implementation Enterprise Administration
Solutions Overview Capabilities Overview Recipes Production Operations Inventory Purchasing Quality Traceability Food Safety Labor Planning Company Brain
All Industries Restaurants Hospitality Catering Production Retail Food Distribution
Work Intelligence Trust
Resource Center Customer Stories ROI Pricing Support
About How We Operate Media Trust Center Procurement Contact
Sign In Book a Demo
Home · Security · Vulnerability Disclosure Policy

Vulnerability Disclosure Policy

Vulnerability disclosure program terms.

Version
1.0
Effective
August 1, 2026
Last updated
August 1, 2026
Document ID
LEGAL-SEC-003
Download PDF Contact Legal Contact Privacy

On this page

  1. 1. Purpose
  2. 2. Scope
  3. 3. Vulnerability Intake Sources
  4. 4. Severity Classification
  5. 5. Remediation Targets
  6. 6. Customer Notification
  7. 7. Coordinated Disclosure
  8. 8. Vulnerability Management Program
  9. 9. Exceptions and Risk Acceptance
  10. 10. Metrics and Review
  11. 11. Contact

All legal documents

Vulnerability Disclosure Policy

This Vulnerability Disclosure Policy ("Policy") describes how MiseCentral LLC ("MiseCentral," "we," "us," or "our") receives, classifies, remediates, and discloses security vulnerabilities affecting the Services. This Policy works together with the Responsible Disclosure Policy, which governs researcher conduct and reporting channels.

1. Purpose

1.1. MiseCentral is committed to identifying and remediating security vulnerabilities in the Services in a timely, risk-based manner to protect Customer Data, operational integrity, and platform availability.

1.2. This Policy establishes internal and external expectations for vulnerability intake, severity assessment, remediation timelines, and coordinated disclosure.

2. Scope

2.1. This Policy covers vulnerabilities in:

(a) MiseCentral-hosted application code, APIs, and administrative interfaces;

(b) MiseCentral-managed cloud infrastructure supporting the Services;

(c) MiseCentral authentication, authorization, Support Mode, and Partner Support Mode mechanisms; and

(d) MiseCentral-operated integration endpoints and Marketplace infrastructure where enabled.

2.2. Vulnerabilities in third-party Subprocessors, Connected Services, Customer-managed devices, or partner systems are addressed through vendor management, Customer governance, or partner coordination as appropriate, and may fall outside direct remediation by MiseCentral.

3. Vulnerability Intake Sources

3.1. MiseCentral receives vulnerability information through:

(a) external reports submitted under the Responsible Disclosure Policy;

(b) internal discovery through secure development, code review, automated scanning, and penetration testing;

(c) Subprocessor and vendor notifications;

(d) Customer or Partner reports through support or security channels; and

(e) threat intelligence and public advisory sources.

3.2. All intake channels route to MiseCentral's security function for triage and tracking.

4. Severity Classification

4.1. MiseCentral classifies validated vulnerabilities using an internal severity model informed by industry practice, considering exploitability, authentication requirements, data exposure potential, scope of impact, and effect on confidentiality, integrity, or availability of the Services or Customer Data.

4.2. Severity levels guide remediation priority:

(a) Critical — vulnerability reasonably permitting unauthorized access to Customer Data at scale, unauthenticated remote code execution on production systems, or widespread service compromise without meaningful mitigating controls.

(b) High — vulnerability permitting privileged unauthorized access, significant authentication bypass, or substantial data exposure under common configurations.

(c) Medium — vulnerability requiring specific conditions or authenticated access, with limited blast radius or meaningful compensating controls.

(d) Low — vulnerability with minimal practical impact, difficult exploitation, or defense-in-depth weakness without direct data exposure.

(e) Informational — observation that does not constitute an exploitable vulnerability but may inform hardening.

4.3. Severity assignments are re-evaluated as new information emerges.

5. Remediation Targets

5.1. Upon validation, MiseCentral targets remediation or implementation of compensating controls according to severity:

(a) Critical — begin containment immediately; target remediation or verified mitigation as rapidly as practicable.

(b) High — target remediation within commercially reasonable timeframes commensurate with risk.

(c) Medium and Low — schedule remediation according to engineering capacity and risk priority.

(d) Informational — address as part of continuous improvement unless elevated by context.

5.2. Targets are goals, not guarantees. Complex vulnerabilities, dependency on third parties, or required Customer configuration changes may extend timelines. MiseCentral will communicate material delays to affected parties where appropriate.

5.3. Emergency changes follow MiseCentral's change management procedures with expedited review appropriate to incident risk.

6. Customer Notification

6.1. Where a validated vulnerability materially affects the security of Customer Data or requires Customer action, MiseCentral will notify affected Customers through support channels, in-product notices, or email in accordance with the Agreement, DPA, and applicable law.

6.2. Notifications will describe, to the extent known: the nature of the vulnerability; affected components; remediation or mitigation status; recommended Customer actions, if any; and contact information for follow-up.

6.3. MiseCentral will not disclose Customer-specific exploit details in public advisories.

7. Coordinated Disclosure

7.1. MiseCentral coordinates public disclosure of material vulnerabilities after remediation or verified mitigation is available, unless earlier disclosure is required by law or necessary to protect Customers.

7.2. External reporters who comply with the Responsible Disclosure Policy may receive advance notice of planned disclosure timing.

7.3. Public advisories are published on MiseCentral's security communications channels and may include CVE identifiers where applicable.

7.4. MiseCentral credits external reporters in public advisories when the reporter consents and MiseCentral determines credit is appropriate.

8. Vulnerability Management Program

8.1. Dependency Management. MiseCentral monitors third-party dependencies for known vulnerabilities and applies updates according to the Secure Development Policy.

8.2. Penetration Testing. MiseCentral conducts penetration testing and security assessments on a risk-based schedule. Results feed remediation backlogs.

8.3. Regression Prevention. Remediated vulnerabilities are covered by tests or monitoring where practicable to prevent recurrence.

8.4. Support Mode Hardening. Vulnerabilities affecting Support Mode or Partner Support Mode receive elevated priority due to privileged assistance context.

9. Exceptions and Risk Acceptance

9.1. Where immediate remediation is infeasible, MiseCentral may implement compensating controls and document risk acceptance with appropriate internal approval until permanent remediation is complete.

9.2. Risk acceptance records include justification, owner, review date, and affected systems.

10. Metrics and Review

10.1. MiseCentral tracks vulnerability intake volume, time-to-remediate by severity, and recurring vulnerability classes to inform security investment.

10.2. This Policy is reviewed at least annually and after material security events.

11. Contact

Vulnerability reports and disclosure inquiries:

MiseCentral LLC Attn: Security — Vulnerability Disclosure 8 The Green, Suite A Dover, DE 19901 United States security@misecentral.com

Version history

VersionEffectiveSummary
1.0August 1, 2026Initial publication of the Legal Library (LEGAL-01).

Previous versions remain available for reference and are never overwritten.

MiseCentral

The Adaptive Operating System for Hospitality—smoother operations, adaptive intelligence, and people in command.

Product

Product Tour Platform Work Intelligence Solutions Industries Pricing

Trust

Trust Center Legal Privacy Security Status Responsible AI

Company

About Resources Support Procurement Contact Book a Demo
© MiseCentral LLC. All rights reserved. · Terms · Privacy · Cookies · Trust Center · Trademark