FireCore — Coordinated Vulnerability Disclosure Policy Koordinovaná politika zverejňovania zraniteľností Full policy / Plné znenie: https://firecore.sk/security Contact / Kontakt: support@firecore.sk Last updated / Posledná aktualizácia: 2026-08-17 --- English --- Please report security vulnerabilities privately to support@firecore.sk. Do not open a public issue. Include: description and impact, steps to reproduce, affected component (mobile / web / API), and version. Do not include real personal data of third parties. Our commitment (coordinated disclosure): - Acknowledgement within 3 business days. - Triage and severity classification per CVSS v3.1 within 7 business days. - Remediation deadlines, running from the report or our own discovery and not from the end of triage: actively exploited vulnerability mitigation within 24 hours and fix within 72 hours; Critical (CVSS >= 9.0) 7 calendar days; High (CVSS 7.0-8.9) 30 calendar days; Medium and low next planned release. - Where a fix depends on a third party the deadline runs from the day that fix becomes available; objective technical obstacles extend it by at most 14 calendar days, and only with an effective mitigation within 24 hours. Safe harbour: we will not pursue legal action against good-faith researchers who avoid privacy violations, data destruction and service disruption, access no more data than needed to demonstrate an issue, give us reasonable time to fix before disclosure, and do not use social engineering, physical attacks or (D)DoS. Testing must stay within your own account and your own fire brigade. Scope: FireCore mobile app (iOS/Android), web (https://firecore.sk, https://app.firecore.sk), API (https://api.firecore.sk). Out of scope: third-party platforms (Railway, Vercel, Cloudflare, OneSignal, Google/Apple). Supported versions: security updates cover the latest released mobile version and the current production web and API. Please update before reporting. Support period (Art. 13(8) of Regulation (EU) 2024/2847): placed on the market 2026-06-01, end of support period 06/2031. Security updates are free of charge for the whole period. --- Slovensky --- Zraniteľnosti nahláste súkromne na support@firecore.sk. Neotvárajte verejný issue. Uveďte: popis a dopad, kroky na reprodukciu, dotknutý komponent (mobil / web / API) a verziu. Nevkladajte reálne osobné údaje tretích osôb. Náš záväzok: potvrdenie do 3 pracovných dní, triage a závažnosť podľa CVSS v3.1 do 7 pracovných dní. Lehoty opravy plynú od nahlásenia alebo zistenia, nie od dokončenia triage: - aktívne zneužívaná zraniteľnosť: zmiernenie do 24 hodín, oprava do 72 hodín - Kritická (CVSS >= 9,0): do 7 kalendárnych dní - Vysoká (CVSS 7,0-8,9): do 30 kalendárnych dní - Stredná a nízka: v najbližšej plánovanej aktualizácii Ak oprava závisí od tretej strany, lehota plynie odo dňa sprístupnenia jej opravy; objektívne technické prekážky ju predlžujú najviac o 14 kalendárnych dní a len pri účinnom zmiernení do 24 hodín. Safe harbour: voči výskumníkom v dobrej viere nepodnikneme právne kroky. Testovanie musí prebiehať v rámci vlastného účtu a vlastnej hasičskej jednotky.