POLICY DOCUMENT

Coordinated Disclosure Policy

Ciphraxis generally follows coordinated vulnerability disclosure. Disclosure timing may depend on vulnerability severity, exploitation risk, vendor responsiveness, remediation availability, and public safety.

01 / Lifecycle

1. Validation

A suspected vulnerability is validated before it is treated as a research finding.

2. Vendor Contact

Ciphraxis attempts to contact the affected vendor or maintainer through an appropriate security channel.

3. Sanitized Advisory

When appropriate, Ciphraxis may publish a sanitized CRX advisory while coordination is ongoing. Such an advisory may contain a CRX identifier, preliminary severity and CVSS, CVE state, disclosure state, and a validated impact summary.

4. Technical Withholding

Technical details that would materially enable exploitation may remain withheld during remediation.

5. Remediation

When a patch or mitigation becomes available, the advisory may be updated.

6. Public Disclosure

After coordinated disclosure, remediation, or another appropriate disclosure point, Ciphraxis may publish additional technical analysis.

02 / Advisory Model

CRX IDENTIFIERS

Ciphraxis advisories use identifiers such as CRX-2026-001. These identifiers remain stable throughout the disclosure lifecycle. A later CVE assignment does not replace the CRX identifier; the CRX advisory remains the canonical Ciphraxis research record.

PRELIMINARY CVSS

When Ciphraxis publishes a CVSS assessment before an external authority or CNA publishes one, it is identified as a Ciphraxis preliminary assessment. Preliminary scores are not official NVD/CNA scores. Scores may change as technical understanding improves, vendor information becomes available, or scope changes.

CVE STATE

Advisories clearly distinguish between CVE assignment states. We do not use "PENDING" as a universal generic state.

  • NOT ASSIGNEDNo CVE identifier exists for this issue.
  • REQUESTEDAn actual CVE request has been submitted to an appropriate CNA.
  • ASSIGNEDA CVE has been officially assigned.
03 / Withholding

REDACTION POLICY

Sanitized advisories may withhold affected product identity, specific vulnerable components, endpoints, payloads, proof-of-concepts, source locations, specific exploitation primitives, or affected version details when publishing that information would materially increase exploitation risk. This decision depends on the disclosure state and risk.

PUBLIC REPOSITORY POLICY

Embargoed vulnerability details are not stored in the public website repository. Redacted values are not hidden with CSS or client-side tricks; they are absent from the public output entirely.