Security

Coordinated Vulnerability Disclosure Policy

Version: 1.0

Effective date: September 3, 2026

1. Purpose

Caphyon develops software products that are used by organizations and individuals worldwide. We recognize that independent security researchers play an important role in improving the security of our products.

This Coordinated Vulnerability Disclosure (CVD) Policy describes how security vulnerabilities affecting Caphyon products should be reported and how Caphyon manages the disclosure process.

Our objective is to investigate reported vulnerabilities promptly, work with reporters in good faith, and provide security updates that reduce risk to our customers.

2. Scope

This policy applies to vulnerabilities affecting software products developed and maintained by Caphyon, including but not limited to:

  • Advanced Installer
  • PacKit
  • ClangPowerTools
  • Advanced Web Ranking
  • Wattspeed
  • BytesRoute
  • associated update mechanisms
  • licensing and activation services
  • cloud services operated by Caphyon that support these products

This policy does not apply to:

  • third-party products
  • vulnerabilities solely affecting customer environments
  • issues requiring physical access to customer systems unless directly caused by a defect in a Caphyon product.

3. Reporting a Vulnerability

Security vulnerabilities should be reported by email to:

security@caphyon.com

Reports should include, where possible:

  • affected product
  • affected version(s)
  • operating system
  • description of the vulnerability
  • steps to reproduce
  • proof-of-concept code, if available
  • potential impact
  • suggested mitigations (optional)

4. What to Expect

Upon receiving a vulnerability report, Caphyon will:

  • acknowledge receipt within three business days
  • perform an initial assessment
  • communicate with the reporter where additional information is required
  • keep the reporter informed of significant progress
  • coordinate public disclosure when appropriate.

Response times may vary depending on the complexity and severity of the reported issue.

5. Coordinated Disclosure

Caphyon supports coordinated vulnerability disclosure.

We ask reporters to:

  • avoid public disclosure before a fix or mitigation is available whenever reasonably possible;
  • allow Caphyon sufficient time to investigate and remediate the issue;
  • communicate with us before publishing technical details.

When appropriate, Caphyon will coordinate publication of:

  • security advisories;
  • release notes;
  • CVE entries;
  • acknowledgements to researchers.

6. Good Faith Security Research

Caphyon supports legitimate security research conducted in good faith.

Researchers acting in accordance with this policy should:

  • avoid actions that could harm customers or disrupt production services;
  • avoid unauthorized access to customer data;
  • avoid modifying or deleting data;
  • avoid denial-of-service testing against production systems;
  • avoid social engineering attacks against Caphyon personnel;
  • immediately discontinue testing if unintended access to sensitive information occurs.

Caphyon will not pursue legal action against researchers who conduct security research responsibly, in good faith, and in accordance with applicable laws and this policy.

Nothing in this policy authorizes activities that violate applicable laws or regulations.

7. Vulnerability Handling

Each reported vulnerability is evaluated according to Caphyon’s internal vulnerability management process.

Reported vulnerabilities are assessed based on factors including:

  • exploitability;
  • impact;
  • affected customers;
  • availability of mitigations;
  • severity.

Where appropriate, Caphyon uses the Common Vulnerability Scoring System (CVSS) to assist in assessing severity.

8. Security Updates

Where a reported vulnerability is confirmed, Caphyon will determine the appropriate remediation, which may include:

  • software updates;
  • patches;
  • configuration guidance;
  • temporary mitigations;
  • security advisories.

The timing of security updates depends on the severity, complexity, and potential impact of the vulnerability.

9. Researcher Recognition

With the researcher’s consent, Caphyon may acknowledge individuals or organizations that responsibly disclose verified vulnerabilities.

Researchers may request to remain anonymous.

10. Privacy

Information provided during the vulnerability disclosure process will be handled in accordance with applicable privacy laws and used solely for investigating, remediating, and coordinating disclosure of reported vulnerabilities.

11. Contact

Security reports:

security@caphyon.com

General support. please contact the product-related team:

https://www.advancedinstaller.com/contact

https://www.advancedwebranking.com/contact