Coordinated Vulnerability Disclosure (CVD) Policy

SUNCAR is committed to continuously optimizing the security of its products. We welcome the support of customers, partners, and independent security researchers who help us identify potential security vulnerabilities.

1.
Vulnerability Policy & Criteria

For a report to be classified as a validated vulnerability and processed under this CVD process, the following requirements must be met:

  • The vulnerability must directly affect one of SUNCAR’s products or digital infrastructure.
  • The vulnerability report must refer to information not yet publicly known.
  • The report must not be merely the result of automated tools or scans without supporting documentation/context.

2.
SUNCAR’s Commitments to the Reporter

SUNCAR guarantees the reporter adherence to the following principles:

  • Confidentiality: Every incoming report will be treated confidentially to the extent permitted by law. Information that is strictly required for public disclosure of the vulnerability is excluded from this.
  • Data Privacy: Personal data of the reporter will not be shared with third parties without their express consent (see our [Link: Privacy Policy]).
  • No NDA Requirement: SUNCAR does not require the reporter to sign a non-disclosure agreement (NDA) at any time.
  • Willingness to Engage: SUNCAR is available as a reliable partner for trustworthy dialogue throughout the entire CVD process.
  • Legal Protection (Safe Harbor): SUNCAR will not initiate criminal proceedings against the reporter as long as this policy and its code of conduct have been followed. This expressly does not apply if recognizable criminal intent was or is being pursued.

Guaranteed Response Times (SLAs):

  • Within 5 business days: You will receive an initial, non-automated response to your vulnerability report or to an update (does not apply to anonymous reports).
  • Within 10 business days: After analysis has been completed, you will receive detailed feedback. This includes at minimum:
    • An explanation of whether SUNCAR confirms or rejects the security vulnerability, or
    • Meaningful follow-up questions to understand the vulnerability, or
    • A justification for why the investigation is taking longer, combined with a commitment to provide an update within an additional 10 business days.

3.
Code of Conduct for the Reporter

To protect reporters who act in good faith, we expect adherence to the following rules. (Note: Reports from parties who do not fully comply with this code will still be processed to the best of SUNCAR’s ability—however, the right to attribution will be forfeited in such cases).

  • No Abuse: The vulnerability must not be exploited abusively. No damage may be caused.
  • No Aggressive Attacks: Attacks such as social engineering, spam, (distributed) DoS, or brute-force attacks against SUNCAR’s IT systems or infrastructure are strictly prohibited.
  • Third-Party Integrity: No manipulation, compromise, or modification of third-party systems or data may be performed.
  • No Exploit Trading: The reporter must not offer tools for exploiting the vulnerability (whether for a fee or free of charge, e.g., on darknet markets) that third parties could use for criminal activities.
  • Content of References: In any subsequent publication, no inappropriate aliases or names may be used for attribution.

4.
Open Communication & Respect

  • Already Remediated Vulnerabilities: SUNCAR reviews and accepts information about already remediated vulnerabilities, even if they can no longer be processed under the CVD process.
  • Contact Information: To promote open communication, we request contact details (preferably email address or phone number).
  • Respectful Conduct: We maintain respectful conduct. Inappropriate behavior (e.g., discrimination, sexism, or insults) will not be tolerated.
  • Status Inquiries: SUNCAR expressly welcomes active inquiries regarding the current processing status.

5.
Public Disclosure of Vulnerabilities

  • 90-Day Deadline: Validated and verified vulnerabilities will be publicly disclosed within a maximum of 90 days.
  • Exception Prior to Market Release: This does not apply if SUNCAR becomes aware of a vulnerability and remediates it before the affected product is even placed on the market.
  • Deadline Extension: With sound justification, the deadline may be extended once by an additional 90 days in close coordination with the responsible national CSIRT. In exceptional cases, further extensions are possible through the CSIRT.
  • EUVD Registration: Public disclosure will be made upon SUNCAR’s request in coordination with the national CSIRT or ENISA, at minimum in the European Vulnerability Database (EUVD).

6.
End of the CVD Process

SUNCAR will notify the reporter of the end of the process without delay (except for anonymous reports). The process is considered complete when:

  • the information in the report proves to be unfounded.
  • the vulnerability of a service (e.g., a web service) has been remediated and publicly disclosed.
  • the vulnerability has been remediated/mitigated through an appropriate patch and publicly disclosed.
  • the reporter has not responded to technical inquiries for at least 30 days.
  • the vulnerability has been publicly disclosed and, in coordination with the national CSIRT, it is no longer expected that the vulnerability will be further mitigated or remediated.
Contact us
Scroll to Top