Skip to main content
Review and revision metadata
Review Date: 2026-06-16
Reviewer: Director

previous version on gdrive

Coordinated Vulnerability Discosure Policy

1. Objective

The purpose of this policy is to establish an authoritative governance framework for Coordinated Vulnerability Disclosure (CVD). This policy outlines the principles, reporting pathways, and administrative boundaries required to identify, report, and remediate technical vulnerabilities discovered within anDREa B.V. (hereafter "anDREa") information systems, ensuring continuous security posture alignment and full stakeholder protection.

2. Scope

The scope of this policy applies to all external perimeters, web applications, and cloud infrastructures owned, operated, or managed by anDREa. This includes, but is not limited to, the primary root domains and their associated subdomains:

  • *.andrea-cloud.com
  • *.mydre.org

This policy aligns with ISO/IEC 27001:2023 Control A.05.24 (Information security incident management), Control A.08.08 (Management of technical vulnerabilities), and the mandatory coordinated vulnerability disclosure framework provisions established under Article 21 of the European Union NIS 2 Directive.

3. Availability and Access

This document is:

  • Required reading for all anDREa employees and contractors.
  • Available to all authorized interested parties, platform users, security researchers, and the public via our official ISMS repository.

4. Operational Foundations of Coordinated Disclosure

The anDREa Coordinated Vulnerability Disclosure framework is governed by two core operational pillars:

4.1 Responsible Stewardship & Purposeful Engagement

The platforms and cloud infrastructure delivered by anDREa are provisioned strictly for their intended corporate and scientific research functions. Any attempt to exploit, disrupt, or manipulate these facilities beyond their explicit design parameters is an operational violation. If a user or researcher uncovers a potential security deficiency through normal interaction, they are expected to maintain containment and submit a discreet report to minimize stakeholder risk.

4.2 Coordinated Governance Authority

  • anDREa Sovereign Infrastructure: anDREa retains absolute, exclusive administrative authority over its core platform services, cloud networks, and centralized software codebases. Technical remediation, vulnerability triage, and infrastructure patches are driven solely by the internal security team.
  • Client Tenant Autonomy: For incidents involving localized data perimeters or tenant-specific structures, the respective client organization maintains full autonomous responsibility over their internal data layers and localized incident responses. anDREa operates strictly under the explicit instruction of the client organization in these scenarios.

5. Prohibition of Unauthorized Intrusions and Active Probing

This policy functions as a reporting pathway for good-faith discoveries made during routine operations; it does not grant authorization, license, or invitation to actively probe systems.

  • Explicit Restrictions: Actively running automated security scanners, probing system logic, conducting unapproved penetration tests, or executing targeted fuzzing campaigns against anDREa domains is strictly prohibited without prior written authorization from the Management Team.
  • Enforcement Thresholds: Unauthorized security assessments or aggressive probing attempts will trigger automated network perimeters and threat logs. Due to strict contractual and regulatory compliance frameworks (such as NIS 2), verified malicious activity or reckless testing will be escalated to legal counsel and appropriate national authorities.

6. Binding Guidelines for Good-Faith Vulnerability Submission

To preserve data privacy and avoid service degradation, any party identifying a security vulnerability during normal service interactions must strictly adhere to the following sequence:

  1. Prompt Communication: Submit details immediately via email to security@andrea-cloud.com. If the vulnerability involves highly sensitive architectural flaws or requires secure evidence transmission, anDREa will provision an isolated, high-security myDRE Workspace for file transfers.
  2. Blast Radius Isolation & Access Minimization: Access and file downloads must be kept to the absolute minimum necessary to prove the security flaw. For example, capturing a directory listing is sufficient proof of unauthorized access; copying, opening, or caching files within that directory is strictly prohibited.
  3. Data Preservation: Do not alter, overwrite, insert dummy records, or delete any configuration setting or data asset on the host system.
  4. Data Sovereignty Maintenance: Do not disclose, replicate, or share personal data or proprietary business information exposed by the vulnerability with any third party.
  5. Strict Embargo: Maintain complete confidentiality. Do not publicly disclose or leak the security finding to any external entity or public advisory board until the vulnerability has been permanently resolved and a public statement is mutually agreed upon.
  6. Reproducibility Metrics: Provide clear, structured, and actionable documentation (such as step-by-step instructions, proof-of-concept payloads, or specific request headers) to enable the engineering team to reliably reproduce the anomaly.

7. Service Level Commitments for Incident Remediation

Upon the formal intake of a verified vulnerability report submitted in good-faith, anDREa commits to the following operational actions:

  • Triage Acknowledgment: anDREa will verify and acknowledge receipt of the incoming report within one working day.
  • Progress Tracking: The security operations team will provide transparent status updates to the reporter throughout the verification and technical remediation lifecycle.
  • Identity Protection: If the researcher requests anonymity, anDREa will safeguard their identity and personal details from external exposure unless compelled to disclose by a legally enforceable court order.
  • Pre-Disclosure Notification: If the anDREa Management Team determines that a vulnerability requires a public advisory to protect the broader ICT or healthcare research communities, the original reporter will be notified prior to the public release.
  • Due Credit Attribution: Upon mutual agreement and successful patch deployment, the researcher will be formally credited as the discoverer in public security statements.
  • Financial Position: anDREa operates purely on a non-monetary basis to focus resources entirely on platform resilience. The organization does not issue cash bounties or financial rewards.

8. Telemetry, Transparency, and Compliance Archiving

To ensure full regulatory accountability to client organizations and external auditors, all resolved security vulnerabilities and subsequent system adjustments are formally closed and documented within the master Information Security Management System repository (https://isms.andrea-cloud.com). Permanent records are archived within the dedicated Issues and Risk Logging and compiled inside formal CTO-Reports (under Management Reports).