Product Security
Vulnerability response process
Lysora follows a consistent process to assess product security reports and communicate verified risk.
- 01Receive and acknowledge the report
- 02Validate impact and affected products
- 03Develop and verify remediation
- 04Coordinate disclosure and publish an advisory
- 05Track follow-up actions and revisions
Target remediation times
Acknowledgement within 24 hours
| CVSS 3.1 rating | Score | Temporary mitigation | Formal resolution |
|---|---|---|---|
| CRITICAL | 9.0-10.0 | Within 7 business days | Within 30 business days |
| HIGH | 7.0-8.9 | Within 7 business days | Within 30 business days |
| MEDIUM | 4.0-6.9 | Within 14 business days | Within 60 business days |
| LOW | 0.1-3.9 | Within 30 business days | Within 180 business days |
