We are currently formalizing our CRA-framework and the related product security procedures within Scanshare Applications B.V. (Scanshare). In the meantime, please find below the appropriate contact and escalation information.

Central contact for CRA and product security inquiries Scanshare / reporting channel

Security-related reports can be submitted via: securityATscanshareDOTcom . This contact should be used for CRA-related questions, product security concerns, vulnerability reports, and security incidents affecting Scanshare products or services. We are also evaluating the implementation of a dedicated vulnerability reporting channel to ensure that security reports can be handled in a structured and traceable manner.

Vulnerability and security incident handling

Scanshare reviews reported vulnerabilities and security incidents based on their potential impact and severity. Reports are assessed, investigated and, where applicable, assigned to the relevant development and product teams for remediation.

Depending on the severity and potential impact, actions may include:
– Initial validation and severity assessment
– Identification of affected products and versions
– Assignment of an internal owner
– Root-cause analysis and remediation
– Development and validation of a security update or corrective measure
– Communication with affected customers or partners where appropriate
– Documentation and closure of the incident

For vulnerabilities with a potentially significant security impact, the matter is escalated internally to senior management and the responsible technical and product teams.

Escalation path for critical or reportable events

Critical security events are escalated immediately to Scanshare management and the responsible technical/product owners. The appropriate response, customer communication and, where applicable, regulatory reporting requirements are then determined based on the nature and severity of the event.
 
As part of our CRA readiness program, Scanshare is further formalizing these procedures, including the applicable escalation timelines, responsibilities, and regulatory reporting requirements.
 
We will provide the final dedicated CRA/product-security contact details and reporting procedure once this framework has been formally established.