ASUME

Trust Center

Vulnerability Management

How to report a security issue, how ASUME handles vulnerabilities, and which assurance activities are still coming.

Security reporting

Email security@asume.ai with enough detail for ASUME to reproduce and assess the issue. Do not include Customer Data or exploit a finding beyond what is needed to demonstrate it.

A formal Vulnerability Disclosure Policy with documented scope and safe-harbour expectations is still a roadmap item. Until it is published, this mailbox is the current reporting path.

Vulnerability and patch management

ASUME identifies, assesses, and remediates vulnerabilities according to risk and operational constraints, including how patches are prioritised. Current handling is described in Security Measures.

A standalone vulnerability-and-patch-management standard with named scan cadence is still being formalized and is not independently verified.

Vulnerability service level agreements

ASUME is defining internal service-level targets so that discovered vulnerabilities are tracked from identification to confirmation that the risk has been reduced. Current handling is described in Security Measures.

Published severity-based SLAs and a dedicated Information Security team that monitors those SLAs are not yet in place and are not independently verified.

Vulnerability disclosure policy

A formal Vulnerability Disclosure Policy for independent researchers, with documented scope and safe-harbour expectations, is a roadmap item.

Until it is published, report issues to security@asume.ai as described under Security reporting.

Penetration testing

An independent, third-party penetration test of the production Service is a roadmap item.

Listing penetration testing here is not a representation that a report currently exists or that an annual test is under contract.