Security & CVE Resolution Policy– Neutrinos Platform

At Neutrinos, security is a core pillar of our platform engineering. As part of our commitment to transparency and trust, we want to share how we handle security vulnerabilities and CVEs (Common Vulnerabilities and Exposures) identified outside of our regular release cycle.

Our Standard Practice

The Neutrinos platform undergoes rigorous Vulnerability Assessment & Penetration Testing (VAPT) and CVE scanning before every release. This ensures that known vulnerabilities are addressed before code reaches your environment.

However, new vulnerabilities can be discovered at any time — between releases, through third-party disclosures, or via emerging threat intelligence. For these cases, we follow a structured resolution SLA based on severity.

Resolution Turnaround Times (TAT)

:red_circle: Critical — Immediate Resolution Within 7 Days

These pose an active or imminent risk and are treated with the highest urgency. Patches or mitigations are fast-tracked regardless of release schedules.

:orange_circle: High — Resolved Within 30 Days

Significant vulnerabilities that require prompt attention. A dedicated fix is prioritized in the next available release window.

:yellow_circle: Medium — Resolved Within 90 Days

Vulnerabilities with moderate risk are tracked and addressed in upcoming planned releases.

:green_circle: Low — Resolved Within 1 Year

Minor or informational findings are logged and remediated as part of ongoing platform hygiene.

What This Means for You

Any security issue newly identified between releases will be handled according to the above TAT, ensuring you always have a clear expectation of when a fix will be available.

We remain committed to proactive security and will continue to improve our processes as the threat landscape evolves. If you have questions or wish to report a vulnerability, please reach out to our support team.


-Neutrinos Platform Team