Skip to content
COORDINATED VULNERABILITY DISCLOSURE POLICY

COORDINATED VULNERABILITY DISCLOSURE POLICY

Retano Shelfplan

Regulation (EU) 2024/2847 (Cyber Resilience Act), Annex I, Part II


1. Purpose and Scope

Retano welcomes reports of vulnerabilities in its products and is committed to responding to them responsibly. This policy describes how to report a vulnerability and how we handle it.

Scope: the Retano Shelfplan product and all of its components (Shelfplan Center, Store BackOffice, Store Portal, Mobile App). Reports are accepted for versions within their support period, as defined in the product documentation.

Security updates addressing reported vulnerabilities are issued for versions within their support period. New functional releases, version migrations, and any associated implementation, configuration or professional services remain subject to Retano’s commercial terms and are outside the scope of this policy. Products, services and infrastructure other than those listed above are not covered by this policy.

2. How to Report a Vulnerability

Single point of contact: security@retano.ai

Please do not include personal data, customer data or production credentials in your initial report. If exchanging sensitive material becomes necessary, we will agree a suitable channel with you.

Please include: a description of the vulnerability and its potential impact, the affected component and version, steps to reproduce (PoC), and, where available, any suggested remediation.

3. What We Ask of Researchers

  • Allow us a reasonable period to remediate the vulnerability before public disclosure (see Section 5).
  • Do not exploit the vulnerability to cause harm, do not access data belonging to others beyond what is necessary to confirm the finding, and do not disrupt the availability of any service.
  • Do not disclose details to third parties before the agreed disclosure date.

4. Safe Harbour

If you act in good faith and within the terms of this policy, Retano will not initiate legal proceedings against you and regards such research as authorised. If you inadvertently access personal or confidential data, stop and notify us immediately.

5. Our Commitments and Timelines

  • Acknowledgement of receipt — within 3 business days.
  • Initial assessment and prioritisation — within 10 business days.
  • Progress updates and agreement of a disclosure date.
  • Remediation without undue delay; the target period for coordinated disclosure is 90 days from acknowledgement of receipt (this may be adjusted according to complexity).
  • Once remediated — release of a security update, publication of an advisory identifying the version in which the vulnerability is fixed, and, where the reporter consents, acknowledgement of the reporter.

6. Out of Scope

The following are generally not considered: social engineering, physical access, volumetric denial-of-service or load testing, and automated scanner output without a demonstrated impact.

7. Relationship to CRA Obligations

Independently of the disclosure process, where an actively exploited vulnerability or a severe incident is identified, Retano notifies the Italian CSIRT and ENISA through the CRA Single Reporting Platform within the applicable deadlines (24 h / 72 h / final report) and informs affected customers.

8. No Rewards

Retano does not operate a bug bounty programme and does not offer monetary or other compensation for vulnerability reports. Submitting a report does not create any entitlement to payment, and Retano accepts no obligation to purchase, license or otherwise acquire any information submitted.

By submitting a report you grant Retano an unrestricted right to use the information it contains for the purpose of assessing and remediating the vulnerability and informing affected customers and authorities.

9. General

Retano may amend this policy at any time. The version in force is the version published at https://retano.ai/security; the version in force at the time your research was carried out is the version that applies to that research. Nothing in this policy constitutes an admission as to the existence, severity or cause of any vulnerability.


Policy owner: Product Security, Retano R&D — security@retano.ai

Version / date: rev. 1.0 / 13.08.2026

Skip to content