Article 14 reporting applies from 11 September 2026
Menu
Article 14 reporting applies from 11 September 2026

Vulnerability disclosure

Effective August 2026

PartsProof welcomes reports of security vulnerabilities in this site and in the packs we deliver, from anyone — security researchers, customers and users. This page is our coordinated vulnerability disclosure policy. Our machine-readable contact is at partsproof.thecompound.tech/.well-known/security.txt (RFC 9116).

How to report

Email hello@thecompound.tech with a description of the issue and where it lives, steps to reproduce, the impact you believe it has, and how you would like to be credited, if at all.

What we commit to

Acknowledgement within 2 business days. An initial assessment, including whether we consider it in scope and our severity view, within 10 business days. Progress updates at least every 14 days while the issue is open. Credit in the fix note if you want it.

Scope

In scope: partsproof.thecompound.tech and its API routes, the free SBOM generator, and the contents of packs we have delivered. Out of scope: third-party services we do not operate, findings that require physical access to a device we do not control, and volumetric denial-of-service.

Rules of engagement

Please give us a reasonable chance to fix an issue before disclosing it publicly, and do not access, modify or delete data that is not yours. Test against your own account and your own repositories. We will not pursue legal action against anyone who reports in good faith under this policy.

Relationship to the Cyber Resilience Act

This policy is the same shape as the one we prepare for customers. Article 14 of Regulation (EU) 2024/2847 requires manufacturers to report an actively exploited vulnerability to ENISA and their CSIRT within 24 hours of becoming aware of it, a fuller notification within 72 hours, and a final report within 14 days of a corrective or mitigating measure being available. Those reporting obligations apply from 11 September 2026.

The machine-readable contact is /.well-known/security.txt.