Argevide
2.09.2026, version 1.0
Purpose and scope
We are committed to the security of the PREMIS software product. This policy explains how you can report a suspected security vulnerability in our software and how we handle such reports. It applies to all products and services we make available in the European Union.
How to report a vulnerability
Please report the vulnerability by email to support@argevide.com or using our contact form.
To help us diagnose and remediate the issue, include where possible: the affected product and version, a description of the vulnerability, steps to reproduce it, its potential impact, and any relevant technical details (logs, proof-of-concept, configuration). You may report anonymously.
What we ask of you (good-faith research)
We support good-faith security research. When investigating, please: avoid privacy violations, data destruction, and service disruption; only access data necessary to demonstrate the issue; do not exploit the vulnerability beyond what is needed to confirm it; and give us reasonable time to remediate before public disclosure. We will not pursue legal action against researchers who act in good faith and in accordance with this policy.
Do not share or publicise the issue with anyone else until it has been fixed.
Our commitments and process
Upon receiving a report we will:
- Acknowledge receipt as soon as possible, within 3 business days.
- Assess and validate the reported vulnerability and keep you informed of our progress.
- Keep you informed of our progress to fix the issue and contact you for additional details when needed.
- Work to remediate confirmed vulnerabilities without undue delay and provide security updates free of charge.
- Coordinate the timing of any public disclosure with you, so that a fix is available before details are released.
- Publicly disclose information about the fixed vulnerability once a remediation or update is available, together with advisory information.
Coordinated disclosure and reporting to authorities
We follow a coordinated disclosure approach: vulnerability details are shared with the public only after a remedy is available, or as otherwise agreed with the reporter. Where required under Regulation (EU) 2024/2847 (the Cyber Resilience Act), we notify actively exploited vulnerabilities and severe incidents to ENISA and the relevant national CSIRT within the applicable timelines.
You may also report a vulnerability in our products indirectly — and, where requested, anonymously — to the CSIRT designated as coordinator in your EU Member State.