Reporting cases and deadlines

A case is opened only after a human confirmed reportability and the awareness time. Deadlines are computed server-side from the ruleset snapshot (24h, 72h, 14 days after a corrective measure / one month after the notification for incidents) and persisted. Alerts fire once per threshold (half window, 6h, 3h, 1h, overdue) to email, in-app, Slack/Teams and PagerDuty.

Reporting assistant

Deterministic checks over recorded facts: required fields, contradictions (awareness in the future, member-state mismatch, exploitation claims without a recorded signal), timeline (late submissions, out-of-order stages), evidence (missing receipts), affected products and mitigation. Optional AI drafts are labelled and require review.

Field provenance

Each generated field shows its source record, last update and author — Product Registry, Organisation profile, Vulnerability record, Incident record, or "entered by reviewer".

Snapshots and amendments

Marking a stage as submitted freezes a signed snapshot (SHA-256 + HMAC signature + provenance). Submitted content never changes: corrections create an amendment (Revision 2, 3 …) next to the original, requiring a reason and, when enabled, a second approver.

Last updated . This page describes the current release.