INTYGIO

Intygio Trust Center

Security is not a feature. It is the product. Every Digital Product Passport we issue must remain verifiable for decades, across EU member states, and through the post-quantum transition. Every claim on this page is verifiable.

Coordinated vulnerability disclosure

Version 1.1, reviewed 2026-09-06. Manufacturer: Kader Cadre AB, trading as Intygio. Also published as security.txt (RFC 9116).

How to report

Email security@intygio.com. Include what the issue is and what it lets an attacker do, steps to reproduce with requests and payloads, the affected asset and version, your suggested severity, and how you want to be credited. If the issue is exploitable in production now, put [Intygio-URGENT] in the subject.

  • 5 business daysAcknowledgement
  • 10 business daysTriage with a severity and an expected timeline
  • WeeklyUpdates during remediation
  • 90 daysDefault coordinated disclosure window, extended by agreement

No paid bounty programme today. Valid findings are credited by name in the advisory unless you ask for anonymity. No NDA is required, and we never pay for silence.

Scope

In scope

  • dpp.intygio.com and all subpaths (signing and verification API), when deployed
  • api.intygio.com, if deployed
  • trust.intygio.com and intygio.com
  • The intygio-verify web component, latest published bundle
  • The @intygio/sdk package, when published
  • Published container images of Intygio services, when published
  • Anything served from /.well-known/ on Intygio domains

Out of scope

  • Customer environments: passport data, event payloads and branded redirect targets belong to the customer. Report to them.
  • Third-party vendors in our supply chain (DigiCert, GitHub, Cloudflare, Stripe and others). Use their channels.
  • Findings that depend on stolen, phished or brute-forced credentials. The access itself is not the report.
  • Social engineering of staff or customers, physical attacks, load testing without written authorisation.
  • Scanner output without a demonstrated impact path.
  • Best-practice notes without an exploitation impact.

Safe harbour

Research done in good faith under this policy will not be met with legal action by Intygio under the Computer Fraud and Abuse Act, NIS2, Brottsbalken chapter 4 section 8c or equivalent statutes, and not with take-down requests. If a third party acts against you for in-scope good-faith work, we will make our authorisation known to them. To qualify:

  1. Stay in scope.
  2. Do not access, change or destroy data beyond what demonstrates the issue. A proof of access is enough.
  3. Do not affect availability: no volumetric tests, no brute force, no cache flushing.
  4. No social engineering.
  5. Report within five business days of finding the issue.
  6. Coordinate disclosure with us before publishing.

Products, advisories and support period

Under Regulation (EU) 2024/2847, the Cyber Resilience Act, the software we hand to customers is a product with digital elements. The signing and verification API is a service. Both are in scope for this policy.

  • intygio-verify web componentFirst line of intygio-verify.js carries a banner with the version; customElements.get('intygio-verify').version at runtime.
  • @intygio/sdkThe npm package name and version.

A fixed vulnerability in a product is disclosed once the update is available: a note on Updates and a CSAF 2.0 document sent to every organisation whose API key used an affected version. Advisory ids are Intygio-SA-<year>-<nnn>; product ids are <product>-<version>.

Security updates for the web component and the SDK are provided free of charge for at least five years from first supply, or for the product's expected time in use if longer (Article 13(8)).

Our own reporting duties

A report that shows an actively exploited vulnerability or a severe incident in a product starts the Article 14 clock towards the ENISA single reporting platform and CERT-SE. We share the technical details; we do not share your identity without your consent.

  • 24 hours from awarenessEarly warning
  • 72 hours from awarenessNotification
  • 14 days after a fix is available, or one month after the notification for an incidentFinal report