🔥 Pripojenie bytu/domu 0 € + odmena za prechod od konkurencie 3 – 9 mesiacov ZADARMO

ZISTIŤ VIAC

ANTIK Telecom s.r.o.

Politika koordinovaného zverejňovania zraniteľností

Verzia 1.0 · Účinnosť od 11. 9. 2026

1. Úvodné ustanovenia

Táto politika upravuje spôsob nahlasovania, riešenia a koordinovaného zverejňovania bezpečnostných zraniteľností v produktoch s digitálnymi prvkami spoločnosti ANTIK Telecom s.r.o. Hlásenie môže podať ktokoľvek, aj anonymne. Ak sa zraniteľnosť týka komponentu tretej strany použitého v produkte spoločnosti, spoločnosť ju oznámi výrobcovi alebo správcovi komponentu v súlade s čl. 13 ods. 6 CRA.

2. Spôsoby nahlásenia zraniteľnosti

Zraniteľnosti preferujeme nahlasovať e mailom na adresu infosec@antik.sk; do predmetu e-mailu prosíme uviesť „Hlásenie zraniteľnosti“. Ak si to povaha veci vyžaduje, spoločnosť sa môže s oznamovateľom dohodnúť na šifrovanej komunikácii, napríklad použitím PGP alebo zaslaním šifrovaného ZIP súboru s heslom poskytnutým inou cestou, napríklad telefonicky. Doplnkovo možno zraniteľnosť oznámiť aj prostredníctvom národného koordinátora cez portál NBÚ pre koordinované zverejňovanie zraniteľností: https://cvd.nbu.gov.sk/#/.

Každé doručené hlásenie posúdi poverená osoba a spracuje sa podľa postupu v kapitole 3.

Hlásenie musí obsahovať aspoň tieto informácie potrebné na posúdenie zraniteľnosti:

Každé doručené hlásenie posúdi poverená osoba a spracuje sa podľa postupu v kapitole 3.

Hlásenie musí obsahovať aspoň tieto informácie potrebné na posúdenie zraniteľnosti (Informácia/Doplňte údaje do e-mailu):

Dotknutý produkt, systém alebo adresa služby: Dotknutý produkt, systém alebo adresa služby
Popis zraniteľnosti: Stručne opíšte problém.
Bezpečnostný dopad: Uveďte, čo môže zraniteľnosť umožniť alebo spôsobiť.
Kroky na overenie alebo reprodukciu: Uveďte konkrétne kroky, ktorými možno zraniteľnosť overiť.
CVSS alebo odhad závažnosti: Ak viete, uveďte CVSS skóre, CVSS vektor alebo slovný odhad závažnosti.
Dôkazy a prílohy: Priložte snímky obrazovky, výstupy, logy alebo iné podklady, ktoré podporia riešenie zraniteľnosti.
Aktívne zneužívanie: Uveďte, či máte vedomosť, že zraniteľnosť je aktívne zneužívaná.
Verejná dostupnosť informácií: Uveďte, či sú informácie o zraniteľnosti už verejne dostupné, napríklad blog, CVE alebo konferencia.
Predchádzajúce nahlásenie: Uveďte, či ste zraniteľnosť už nahlásili inému subjektu, napríklad SK-CERT alebo výrobcovi komponentu.

3. Postup spracovania hlásení

Spoločnosť sa pri spracovaní hlásení zaväzuje k nasledujúcemu postupu:

a)   potvrdenie prijatia – bezodkladne po doručení hlásenia zašle potvrdenie s referenčným číslom (ak oznamovateľ uviedol kontakt),

b)   posúdenie – bez zbytočného odkladu hlásenie posúdi, overí reprodukovateľnosť a určí závažnosť a plán riešenia,

c)   náprava – zraniteľnosti rieši a napráva bezodkladne vo vzťahu k rizikám, ktorým sú produkty vystavené, a to aj poskytovaním bezplatných bezpečnostných aktualizácií; ak je to technicky možné, bezpečnostné aktualizácie poskytuje oddelene od aktualizácií funkcií,

d)   koordinované zverejnenie – po sprístupnení bezpečnostnej aktualizácie spoločnosť zverejní bezpečnostné oznámenie s opisom zraniteľnosti, dotknutých produktov, dopadov a závažnosti a s pokynmi pre používateľov; zverejnenie možno v riadne odôvodnených prípadoch odložiť dovtedy, kým používatelia nedostanú možnosť aplikovať príslušnú opravu. Do zverejnenia bezpečnostného oznámenia je oznamovateľ viazaný mlčanlivosťou podľa kapitoly 4; skoršie alebo iné zverejnenie je možné len s predchádzajúcim súhlasom spoločnosti.

Hlásenia aktívne zneužívaných zraniteľností sa spracúvajú prioritne; spoločnosť si zároveň plní oznamovacie povinnosti výrobcu podľa čl. 14 CRA voči regulátorom. Tento postup sa nevzťahuje na nepodložené podnety, automatické skeny bez opisu rizika ani služby tretích strán.

4. Pravidlá pre oznamovateľov

Od oznamovateľov sa očakáva konanie v dobrej viere. Pri identifikácii a overovaní zraniteľnosti sa oznamovateľ zdrží najmä:

a)   prístupu k údajom nad nevyhnutný rozsah, ich kopírovania, zmeny alebo mazania,

b)   narúšania dostupnosti služieb, záťažových testov a DoS útokov,

c)   sociálneho inžinierstva, phishingu a fyzických útokov,

d)   zneužitia zraniteľnosti nad rámec jej overenia,

e)   zverejnenia zraniteľnosti pred koordinovaným zverejnením alebo bez súhlasu spoločnosti.

Voči osobám, ktoré konajú v dobrej viere a v súlade s touto politikou, spoločnosť nebude iniciovať občianskoprávne kroky ani podávať trestné oznámenia v súvislosti s činnosťou nevyhnutnou na identifikovanie a oznámenie zraniteľnosti.

ANTIK Telecom s.r.o.

Coordinated Vulnerability Disclosure Policy

Version 1.0 · Effective from 11 September 2026

1. Introductory provisions

This policy governs the reporting, handling and coordinated disclosure of security vulnerabilities in products with digital elements of ANTIK Telecom s.r.o. Anyone may submit a report, including anonymously. Where a vulnerability concerns a third-party component used in a product of the company, the company shall notify the manufacturer or maintainer of that component in accordance with Article 13(6) of the CRA (Cyber Resilience Act, Regulation (EU) 2024/2847).

2. How to report a vulnerability

We prefer to receive vulnerability reports by e-mail at infosec@antik.sk; please use the subject line “Vulnerability report”. Where the nature of the matter requires it, the company may agree with the reporter on encrypted communication, for example using PGP or an encrypted ZIP file with the password provided through a separate channel, such as by telephone. In addition, a vulnerability may also be reported through the national coordinator via the NBÚ (National Security Authority of the Slovak Republic) portal for coordinated vulnerability disclosure: https://cvd.nbu.gov.sk/#/.

Every report received is assessed by a designated person and handled in accordance with the procedure in Chapter 3.

A report must contain at least the following information needed to assess the vulnerability (Information/Please include in your e-mail):

Affected product, system or service address: State the name, version, URL or other identification.
Description of the vulnerability: Briefly describe the issue.
Security impact: State what the vulnerability may enable or cause.
Steps to verify or reproduce: Provide the specific steps by which the vulnerability can be verified.
CVSS or severity estimate: If known, provide the CVSS score, CVSS vector or a verbal estimate of severity.
Evidence and attachments: Attach screenshots, outputs, logs or other material that will support resolving the vulnerability.
Active exploitation: State whether you are aware that the vulnerability is being actively exploited.
Public availability of information: State whether information about the vulnerability is already publicly available, for example in a blog, a CVE record or at a conference.
Previous reporting: State whether you have already reported the vulnerability to another party, for example SK-CERT or the manufacturer of the component.

3. Report handling procedure

When handling reports, the company commits to the following procedure:

a)   acknowledgement of receipt – promptly after receiving a report, the company sends an acknowledgement with a reference number (where the reporter has provided contact details),

b)   assessment – without undue delay, the company assesses the report, verifies reproducibility and determines the severity and a remediation plan,

c)   remediation – the company addresses and remediates vulnerabilities without delay, commensurate with the risks to which the products are exposed, including by providing security updates free of charge; where technically feasible, security updates are provided separately from functionality updates,

d)   coordinated disclosure – once a security update has been made available, the company publishes a security advisory describing the vulnerability, the affected products, the impact and severity, and instructions for users; in duly justified cases, publication may be postponed until users have had the
opportunity to apply the relevant fix. Until the security advisory is published, the reporter is bound by confidentiality under Chapter 4; earlier or other disclosure is possible only with the prior consent of the company.

Reports of actively exploited vulnerabilities are handled with priority; at the same time, the company fulfils its notification obligations as a manufacturer under Article 14 of the CRA towards the regulators. This procedure does not apply to unsubstantiated submissions, automated scans without a description of the risk, or third-party services.

4. Rules for reporters

Reporters are expected to act in good faith. When identifying and verifying a vulnerability, the reporter shall in particular refrain from:

a)   accessing data beyond the extent strictly necessary, and from copying, modifying or deleting it,

b)   disrupting the availability of services, load testing and denial-of-service (DoS) attacks,

c)   social engineering, phishing and physical attacks,

d)   exploiting the vulnerability beyond what is necessary to verify it,

e)   disclosing the vulnerability before coordinated disclosure or without the consent of the company.

The company will not initiate civil proceedings or file criminal complaints against persons who act in good faith and in accordance with this policy in connection with activities necessary to identify and report a vulnerability.