
Coordinated Vulnerability Disclosure Policy
Coordinated Vulnerability Disclosure Policy
CalWin AS welcomes reports of security vulnerabilities in our products. This policy explains how to report a vulnerability to us, what you can expect in return, and the commitments we make to researchers who report in good faith. It supports our obligations under the EU Cyber Resilience Act (CRA), which requires manufacturers to operate a coordinated vulnerability disclosure process and to handle vulnerabilities throughout the product support period.
We do not currently operate a bug bounty programme and cannot offer financial rewards.
Scope
This policy covers the following CalWin products:
- CalWin 7
- CalWin 8
CalWin 8 — we declare a support period of at least five years from the date each version is placed on the market.
CalWin 7 — CalWin 7 is actively supported. We will publish an end-of-support date well before support ends.
During the support period we handle reported vulnerabilities and provide security updates for the product concerned. Where a product's expected lifetime is genuinely shorter than the declared period, we will state this explicitly. We will give advance notice through our normal customer channels before a support period ends.
It also covers the following websites operated by CalWin AS:
calwin.no
calwin.se
calwin.co.uk
calwincloud.com
Third-party services we do not operate are out of scope.
How to report
If you have discovered an issue you want to report, please send an email to our security contact point, security@calwin.no.
Acknowledgement will be sent within 3 business days of receipt.
A good report includes
- The affected product and version.
- A description of the vulnerability and its impact.
- Step-by-step reproduction instructions.
- Any proof-of-concept.
- Your contact details so we can follow up.
Our commitments to you (safe harbour)
If you make a good-faith effort to comply with this policy during your security research, CalWin will:
- Consider your research authorised and will not pursue or support legal action against you for it.
- Work with you to understand and resolve the issue quickly, and acknowledge receipt within 3 business days.
- Keep you informed of progress and, with your consent, credit you when the issue is resolved.
This safe harbour applies only to the extent permitted by applicable law and does not authorise actions covered in the next section.
What we ask of you
- Give us reasonable time to investigate and remediate before disclosing publicly. We propose a coordinated disclosure window of up to 90 days.
- Do not access, modify, or delete data that is not your own. Use only test accounts and test data.
- Avoid privacy violations, service degradation or destruction of data, and do not run denial-of-service or spam/social-engineering attacks against staff or customers.
- Do not exploit the vulnerability beyond what is necessary to demonstrate it.
Our handling process and timelines
On receiving a report we will triage and assess severity, reproduce the issue, develop and test a fix, and coordinate the release of a security update to affected customers. Indicative targets are as follows:
Stage: Acknowledge receipt - Target: ≤ 3 business days
Stage: Initial severity assessment - Target: ≤ 10 business days
Stage: Fix or mitigation plan agreed - Target: Risk-based; critical issues prioritised
Stage: Coordinated public disclosure - Target: Up to 90 days, by mutual agreement