New: the first SBOM scanner for machines.Take a look
Notifier

Inform customers with your own PSIRT

Case management, CSAF advisories and coordinated vulnerability disclosure. Handle vulnerabilities in a structured way, not in email chaos.

Received2CSA-9F21CVE-2024-3094CSA-9F22CVE-2024-2961In progress1CSA-8B04CVE-2022-0547Published1CSA-7A19CVE-2021-44228

Case Management (Kanban)

Manage vulnerability cases in a Kanban board. From "Received" through "In Progress" to "Published", every status at a glance.

CSA-C4F4BCC10CVE-2022-05479.8

Triage: CVE-2022-0547

SCALANCE · RUGGEDCOM · MAXLINE

1 vulnerability · 1 remediationCSAF

CSAF Advisories

Create machine-readable security advisories in CSAF format. Standards-compliant, automatically structured, immediately publishable.

Documents & resources

Security.txt
CVD Policy

security.txt (RFC 9116)

Generate and publish a security.txt according to RFC 9116, so security researchers know how to reach you.

Security contact

PSIRT

Product Security Incident Response Team

CVD Policy
PGP key

Response within 5 business days

CVD Policy

Define your Coordinated Vulnerability Disclosure Policy. Clear rules for researchers, clear processes for your team.

Security contact

psirt@complioty.de

CVE / Titel

Beschreibung

Submit report

Vulnerability Report Intake

A structured intake form for vulnerability reports. Researchers report, your team handles, without email chaos.

imaginary-quill.psirt.complioty.app

Security Advisories

Central information platform for security topics and vulnerabilities.

CSA-C4F4BCC109.8
Triage: CVE-2022-0547

Security contact

PSIRTpsirt@complioty.de

Public Disclosure Page

Your own public page for security advisories, security.txt and CVD policy. Professional and trust-building.

How it works

Three steps to your advisory.

01

Set up in 10 minutes

security.txt, report form and CVD policy are live. From then on researchers can reach you.

02

Reports land in the board

Every report becomes a case your team works through. Critical vulnerabilities from monitoring land in the same board.

supported by Observer

03

Publish the advisory

Record the fix, put the advisory on your disclosure page, report to ENISA if needed. Done.

The difference

Three weeks before anyone notices.
Or in the board from minute one.

By hand3 weeks

The researcher looks for a contact and finds none. So an email to info@ or a post in a forum. Your team hears about it from a customer. Now it is a crisis instead of a process.

With Notifier2 hours

They find your security.txt and report through your form. The case is in the board immediately. Setting all that up takes 10 minutes.

Cyber Resilience Act

December 11, 2027.

From then on, product security is a legal obligation. No evidence, no CE marking.

486
Days
:
11
Hrs
:
19
Min
:
36
Sec

From vulnerability report to advisory, in one workflow.

PSIRT-in-a-Box: Case management, CSAF advisories, and coordinated disclosure.