MILESTONECUI Vault has achieved FedRAMP Moderate equivalency.FedRAMP Moderate equivalency achieved.Read the announcement

Vulnerability Disclosure Policy

Effective June 1, 2026 · Last updated June 2, 2026

CUI Vault, a product of NtelSec, Inc., is committed to protecting our customers and the broader community by quickly addressing security vulnerabilities. We welcome reports from security researchers and members of the public who discover potential vulnerabilities in CUI Vault. This policy explains what is in scope, how to report safely, and what you can expect from us in return.

Security posture

The CUI Vault platform implements 100% of the FedRAMP Moderate baseline, independently assessed by Kratos, a FedRAMP-recognized third-party assessment organization (3PAO).

CUI Vault is not FedRAMP Authorized and NtelSec does not represent that it holds a FedRAMP authorization. FedRAMP Moderate equivalency is the standard described by DoD for cloud service offerings under DFARS 252.204-7012(b)(2)(ii)(D).

Read what the assessment covered, including which components sit inside the authorization boundary and which are the customer’s responsibility.

1. Scope

This policy applies to vulnerabilities that affect CUI Vault-managed systems and services.

In scope:

  • The CUI Vault customer portal and web application.
  • CUI Vault-managed application services and APIs that are publicly reachable.
  • CUI Vault-managed identity and access experiences provided to customers.

Out of scope:

  • Any system, network, or environment operated within a controlled (e.g. GCC High) boundary, which is not publicly reachable and is not a target for outside testing.
  • Customer-owned systems, accounts, devices, or networks not managed by CUI Vault.
  • Third-party services we do not operate, unless the issue is demonstrably caused by our configuration (report those to the relevant vendor).
  • Volumetric denial-of-service, social engineering of staff or customers, and physical attacks.

If you are unsure whether something is in scope, submit a report anyway — our team will review it.

2. How to Report

Email vuln-report@ntelsec.com as soon as possible. To help us triage quickly, please include:

  • A clear description of the vulnerability and its potential impact.
  • The affected product or component (e.g. portal, access path, APIs).
  • Step-by-step instructions to reproduce it (a proof-of-concept is helpful, but not required).
  • Any relevant logs, screenshots, request/response samples, or timestamps.
  • Your contact information for follow-up questions.

3. Do Not Include Sensitive Data

Do not include classified information, Controlled Unclassified Information (CUI), or any other sensitive data in your report or in this form. If a finding requires sharing sensitive detail to demonstrate it, simply say so in your report and we will arrange a secure channel before you send anything further.

4. Guidelines for Testing (Good-Faith Expectations)

We ask that you:

  • Avoid privacy violations and do not access, modify, or destroy data that does not belong to you; use only test accounts and your own data.
  • Use minimal-impact techniques to demonstrate the issue.
  • Stop testing immediately if you encounter sensitive data (including any potential CUI) and report what happened.
  • Do not exfiltrate data — a screenshot or redacted sample is sufficient where applicable.
  • Do not degrade, disrupt, or deny service to our systems or other users.
  • Do not publicly disclose the vulnerability until we have had a reasonable opportunity to investigate and remediate.

5. Coordinated Disclosure and Safe Harbor

If you make a good-faith effort to comply with this policy during your research, we will consider your activity authorized, we will not pursue or support legal action against you, and we will work with you to understand and validate the issue and keep you reasonably informed of remediation progress. If legal action is initiated by a third party against you for activity that complied with this policy, we will make this authorization known.

This safe harbor does not apply to:

  • Intentional data theft or exfiltration.
  • Extortion demands.
  • Service disruption (DoS/DDoS).
  • Social engineering, threats, or harassment.
  • Any activity that violates applicable law or this policy.

6. Our Response Process

After we receive a report, we aim to:

  • Acknowledge receipt within 1–2 business days.
  • Complete initial triage within 5 business days (may be sooner for critical issues).
  • Provide ongoing updates as appropriate based on severity and complexity.
  • Remediate based on risk, exploitability, and impact.

If the report affects customer security, we may coordinate notifications through established customer security contacts.

7. Severity and Prioritization

We prioritize vulnerabilities using industry-standard risk criteria — impact to confidentiality, integrity, and availability, exploitability, and scope. Issues that could impact the confidentiality of regulated data or allow unauthorized access are treated with the highest priority.

8. What We Ask You Not to Do

  • Attempt to access other users’ or tenants’ data.
  • Use automated scanners in a way that degrades service.
  • Perform brute-force attacks or credential stuffing.
  • Attempt to bypass security controls through disruptive methods.

9. Recognition

At our discretion, we may acknowledge security researchers who report valid issues and follow this policy (e.g., by listing a name/handle on an acknowledgments page), unless you prefer to remain anonymous.

10. Submit a Report

Send your report from your own email client to vuln-report@ntelsec.com. Remember: no sensitive data.

Email vuln-report@ntelsec.com