PUBLIC · securepeak.comAS216096 · L-717869-S
SecurePeak
Applied research · CVD

Advisories

Vulnerability discovery, exploit development and adversary behavioural analysis across vendor firmware, cryptographic libraries and CI infrastructure. Every advisory carries a CVSS 3.1 vector, CWE, affected versions and a reproduction transcript, and publishes on day 90 of a clock that starts at vendor notification.

200+
CVEs assigned
90d
Clock, no exceptions
1
Extension, 30d, fix in progress only
Submit research

Coordinated disclosure

PGP-encrypt to 0x5C630EA4 and send to research@securepeak.com with a PoC and affected versions. Acknowledgement within one business day; we co-sign the advisory and never ask for silence beyond the clock.

PGP required
CVD policy v3
The clock

90 days, day by day

  1. DAY 00
    Vendor notified
    Full technical detail, reproduction steps, evidence hash.
  2. DAY 07
    Escalation if unacknowledged
    Second notice; alternate contacts attempted.
  3. DAY 45
    Mid-point check-in
    Draft advisory shared for factual review.
  4. DAY 83
    Final notice
    Seven days to ship, or to request the one extension.
  5. DAY 90
    Advisory published
    Credit as coordinated, if they engaged.