Pixel Federation – Vulnerability Reporting and Coordinated Vulnerability Disclosure
Pixel Federation, s.r.o. (hereinafter referred to as the "Company") takes the security of its products with digital elements seriously and, in accordance with the EU Cyber Resilience Act (CRA), establishes a single point of contact for vulnerability reporting.
1. Contact Information
- Email: [email protected]
- Form: Vulnerability Report Form
- Supported languages: Slovak, English
The contact point is monitored by humans, not solely by automated tools.
2. What the Report Should Include
- A description of the vulnerability and its estimated/potential impact
- Steps to reproduce (detailed steps, PoC, screenshots/video where applicable)
- Affected product / version / URL
- Your contact details (for follow-up, feedback, or potential bounty/recognition)
3. Coordinated Disclosure (Embargo)
We kindly request that the reporter not disclose the vulnerability publicly before the Company implements a fix, or until an agreed-upon date (typically up to 90 days from the initial report, unless otherwise agreed by both parties). The coordinated disclosure date will be agreed upon directly with the reporter.
4. Safe Harbor
The Company will not pursue legal action against reporters who act in good faith, act reasonably, and comply with this policy when discovering and reporting a vulnerability.
5. Legal Basis
This policy is established in accordance with Article 13(11), Article 14, and Annex II of Regulation (EU) 2024/2847 (Cyber Resilience Act).