Security

Security policy

Last updated: 9 September 2026

This is the coordinated vulnerability disclosure policy for every Invarix product. It also records how Invarix meets its reporting obligations as a manufacturer under Regulation (EU) 2024/2847, the Cyber Resilience Act.

Report a vulnerability to security@invarix.dk. You will get a human reply within 48 hours.

What is in scope

The published packages: Invarix.Guard, Invarix.Guard.Professional, Invarix.Guard.Evidence, Invarix.Gate and its adapter and bridge packages.

This website and the licence issuance flow are in scope for reports about the service itself, such as the checkout or the licence email.

Model weight files distributed from the public model releases are in scope for integrity issues, such as a hash mismatch against a published manifest.

How to report

Email security@invarix.dk with the affected package and version, what an attacker can actually do, and the smallest reproduction you have. A failing test, or a policy file plus the tool call that defeats it, is ideal. Tell us if you believe it is already being exploited.

Please do not open a public issue for a suspected vulnerability. If you need encryption, send a first message with no details and we will supply a key.

You may report anonymously. We do not ask you to accept terms before reporting, and we do not ask you to keep quiet about a report once it is fixed.

What you can expect

Acknowledgement from a human within 48 hours. A first assessment with a severity view and a rough plan within 10 working days. A fix or a documented mitigation for confirmed high and critical issues within 90 days of acknowledgement, with the advisory published at the same time.

These are targets from a one-person company rather than contractual commitments, and they are written down here so nobody has to guess. There is no paid bug bounty. Reporters are credited in the advisory unless they ask not to be.

If a fix will take longer than 90 days we will tell you before the 90 days are up, with the reason and a revised date. You are free to disclose publicly after 90 days from acknowledgement whether or not a fix exists. We will not treat good faith research as a licence breach and will not pursue legal action over it.

What is out of scope

Automated scanner output with no demonstrated impact, missing hardening headers with no exploit path, denial of service through deliberately absurd input to a local library, and social engineering of the maintainer.

One recurring non-issue: Gate's free observe mode blocks nothing by design and reports what it would have blocked. That is documented behaviour, not a vulnerability. Enforce mode is the enforcing configuration.

Cyber Resilience Act reporting

Invarix is a manufacturer of products with digital elements under Regulation (EU) 2024/2847. From 11 September 2026, for any actively exploited vulnerability in a product above, and for any severe incident affecting the security of those products, we report on these deadlines:

  • Early warning within 24 hours of becoming aware.
  • Full notification within 72 hours of becoming aware.
  • Final report within 14 days of a corrective measure being available, for vulnerabilities.
  • Final report within one month of the notification, for severe incidents.

Reports are filed once through the CRA Single Reporting Platform, which routes to the CSIRT designated as coordinator for Denmark, our main establishment, and to ENISA.

This obligation is independent of the disclosure timeline above. A vulnerability that is being exploited is reported to the authorities within 24 hours even where a reporter has asked for a longer embargo, because the regulation requires it. Where the two conflict we tell the reporter which parts were reported and when.

We will also inform affected users, without undue delay and where we have a way to reach them, of an actively exploited vulnerability and any corrective measure they need to apply. For licensed products that is the address used at purchase. The free tier has no such channel, so the advisory and the release notes are the notification.

Security update window

The update window follows the licence and is stated there rather than promised open-endedly. A licensed version receives security fixes for the covered window stated in its licence, and the last version delivered inside that window keeps working afterwards but stops receiving fixes. Community versions receive security fixes on the current minor version only.

When a version leaves support, that is recorded in the changelog with a date. We do not silently stop maintaining a version.

What the products do and do not guarantee

These are the claims you can hold us to, with the limits that go with them.

All detection and enforcement runs inside your process. No product sends prompt text, tool arguments, or evidence records to Invarix or to any third party. Licence validation is an offline signature check with no network call.

Gate can only see tool calls routed through an adapter it wraps. A call made on a path that bypasses the adapter is not evaluated. Gate's coverage report exists to make that visible, and it detects such calls where the framework reports them, but it cannot prevent them.

Tools that execute inside a model provider's own service cannot be intercepted before they run. Agents hosted in Azure AI Foundry Agent Service or Copilot Studio are outside the enforcement boundary entirely.

Enforce mode fails closed. A detector that throws denies the call by default, and that default is configurable and visible.

Evidence records are hash chained and signed, and proofs verify offline against a published public key. That makes them cryptographically verifiable and admissible. It does not confer the legal presumption of integrity that under eIDAS belongs only to a ledger operated by a qualified trust service provider.

Contact

security@invarix.dk for vulnerabilities. sales@invarix.dk for everything else.