Bayescope

Security

Reporting a vulnerability.

Bayescope is a security product, so it has to hold up to the same scrutiny it applies to everyone else. If you have found a flaw, here is exactly what happens when you tell us.

Report to bayescope@anhuret.com. Every report is acknowledged and triaged against the published clocks below, and good-faith research is protected by the safe-harbour statement. Reproduce, describe, and tell us before you tell anyone else.

Response targets

Severity drives the clock. Times run from receipt at the contact address; business days are Slovak working days.

SeverityAcknowledgeTriageWhat it means
Critical24 hours48 hoursUnauthenticated remote compromise of the product, a break of tenant isolation, disclosure of stored secrets or of another client's data, or any flaw already being exploited against a Bayescope installation.
High72 hours5 business daysAuthenticated privilege escalation, authorization bypass across roles, injection or deserialization with a plausible path to code execution, or loss of the audit trail's tamper-evidence.
Medium5 business days10 business daysVulnerabilities requiring unusual preconditions or significant user interaction, information disclosure of non-sensitive internals, or denial of service against a single tenant's own workload.
Low10 business days20 business daysDefence-in-depth findings, missing hardening headers on non-sensitive responses, and issues with no demonstrated security impact.

A fix timeline is communicated at triage, per case, together with the severity we assigned and why. We do not publish blanket fix deadlines: a date we cannot keep is worth less to a reporter than an honest schedule agreed once the defect is understood. Where a fix will take longer than the agreed disclosure window, we say so and agree an extension rather than let the date pass in silence.

Disclosure

Disclosure is coordinated. The default window is 90 days from acknowledgement, extendable by agreement, and we will always credit the reporter unless asked not to. Where the vulnerability is being actively exploited, the statutory clocks of the regime applicable to this deployment (below) take precedence over the coordinated window and run in parallel with it.

Our own reporting obligations

EU Cyber Resilience Act (Regulation (EU) 2024/2847) — Article 14, Regulation (EU) 2024/2847, from 2026-09-11

As the manufacturer of a product with digital elements placed on the EU market, Anhuret s.r.o. reports actively exploited vulnerabilities and severe incidents affecting the security of Bayescope on the statutory clocks below.

Actively exploited vulnerability

  • 24 hours — Early warning to the CSIRT designated as coordinator and to ENISA, within 24 hours of becoming aware.
  • 72 hours — Vulnerability notification with general information about the product, the general nature of the exploit and the vulnerability, and any corrective measures taken or advised, within 72 hours.
  • 14 days — Final report describing the vulnerability, its severity and impact, and where available the corrective measures taken, within 14 days of a corrective measure becoming available.

Severe incident affecting product security

  • 24 hours — Early warning within 24 hours of becoming aware.
  • 72 hours — Incident notification with an initial assessment, severity, impact and where available the indicators of compromise, within 72 hours.
  • 1 month — Final report with a detailed description, the type of threat and root cause, and the mitigations applied, within one month of the notification.

Reported through: ENISA single reporting platform, via the coordinating CSIRT

Affected clients are notified without undue delay through the product's own notification channel, with the information needed to judge exposure and the remediation available.

NEEDS EXPERT REVIEW — CRA scope and the precise obligations for this product are being confirmed with counsel. This statement describes the practice Anhuret s.r.o. follows; it is not legal advice.

In scope

  • The Bayescope product — the API, the web application and the mobile client
  • The marketing site and its supporting static content
  • Bayescope container images, the installer and the deployment tooling
  • Content packs distributed over the signed content-update channel

Out of scope

  • Client-hosted installations without that client's written authorisation
  • Third-party systems Bayescope connects to (a client's SIEM, EDR, SOAR, identity provider or ticketing system)
  • Denial-of-service testing, physical attacks, and social engineering
  • Findings from automated scanners with no demonstrated impact

Safe harbour

We will not pursue or support legal action against anyone who reports a vulnerability in good faith under this policy: research confined to the in-scope assets, no access to or exfiltration of data belonging to us or to a client beyond what is necessary to demonstrate the flaw, no degradation of service, no social engineering of our staff or clients, and no public disclosure before the agreed date. If in doubt, ask before you test.

Encryption

No PGP key is published. A fingerprint nobody holds the private half of is a worse outcome than plain email to a monitored address, and every report reaching the contact address opens an auditable case on receipt. If you need an encrypted channel before sending, say so in a first message and we will agree one.

Machine-readable

The same details in RFC 9116 form: /.well-known/security.txt. Policy version 1.1.0.