Researchers report. They are not treated as attackers.
The public CVD intake is separated from internal management. Reports are validated, bounded and admitted with a unique tracking and receipt structure.
Security research needs a safe intake path. Institutions also need durable evidence of when a report arrived, how it was assessed, who authorized each state transition, when remediation was verified, and under which conditions coordinated disclosure occurred. immo.quick binds that lifecycle as governed CVD & Proof Closure.
The public CVD intake is separated from internal management. Reports are validated, bounded and admitted with a unique tracking and receipt structure.
State changes follow a server-enforced transition graph. Invalid jumps are denied; valid transitions create immutable transition receipts or governance events.
Canonical submission hash, policy and receipt version, integrity binding, transition authority, reason and chain link turn the process into a forensic proof path.
Core treats a vulnerability report as governed institutional state. Immutable governance events bind each relevant transition to actor, authorization basis, prior state, next state and a cryptographic event chain. Reporter claims remain separated from internally validated facts.
The Serverless Edition physically separates public CVD intake from internal management, enforces state transitions server-side, and binds each valid transition to an immutable receipt. Public submissions are hardened; tracking requires both report ID and a high-entropy token.
Regulatory value does not come from software replacing a regulator. It comes from an institution not having to merely assert that a vulnerability was handled correctly. Intake, case governance, authorization of critical transitions, remediation, fix verification and actual use of an official reporting channel can be treated as separate, inspectable states.
Operational CVD submission is designed as a separate public system path and is isolated from internal management. This website explains the governance and proof model; it does not replace the operational submission interface of the system.
An evidence-bound lifecycle for intake, triage, authorized state transitions, remediation, fix verification and coordinated disclosure of a vulnerability report.
No. Attack forensics and cooperative vulnerability disclosure are separate processes and separate event models.
No. It is aligned with BSI CVD principles. This does not constitute testing, certification, recognition or a conformity statement by the BSI.
The architecture separates intake receipt, canonical submission hash, policy and receipt versions, transition authority and immutable state sequence. Which artifacts are made public remains a separate disclosure decision.