Knowledge Base Page

Security Disclosure Page

Report a Security Vulnerability

TenAsys is committed to the security of the INtime product family. If you have discovered a potential vulnerability, please contact us using the channel below. We take all reports seriously and will respond promptly.

Security Contact

Vulnerabilities in TenAsys products may be reported through the following channel:

Email: security@tenasys.com

Subject line format: [SECURITY] <product name> — <brief description>

TenAsys monitors this address during normal business hours (8am-5pm Pacific Time, Monday through Friday, excluding US federal holidays). Reports received outside business hours will be acknowledged on the next business day.

TenAsys does not currently offer a web-based vulnerability submission form or a bug bounty program. Reporters who wish to submit anonymously may do so via a CSIRT designated as coordinator under Article 12(1) of Directive (EU) 2022/2555, who may relay the report to TenAsys on their behalf without disclosing the reporter's identity.

What to Include in Your Report

To help us triage and respond effectively, please include as much of the following as possible:

  • Affected product and version (e.g., INtime RTOS 7.x, INtime SDK)
  • A description of the vulnerability, including the type of weakness (e.g., memory corruption, privilege escalation, authentication bypass)
  • Steps to reproduce the vulnerability, including any necessary test environment configuration
  • The potential impact and the conditions under which it could be exploited
  • Whether the reporter believes the vulnerability is currently being actively exploited
  • Any proof-of-concept code or technical artifacts that demonstrate the vulnerability (these will be treated as confidential)
  • Whether the reporter intends to publish their findings, and a proposed timeline
  • The reporter's preferred contact method and, if applicable, their preference for anonymous handling

Our Response Process

Phase Timeframe What Happens
Acknowledge Within 72 hours We confirm receipt and assign a tracking reference.
Assess Within 10 business days Our security team validates the report and determines initial severity.
Remediate Within 90 days* We develop and test a fix, communicating progress throughout.
Disclose Coordinated We work with you on timing and credit for public disclosure.

* Critical vulnerabilities with active exploitation may follow an accelerated timeline. We will notify you in all cases.

Scope

This disclosure policy applies to all TenAsys products, including:

  • INtime RTOS & Runtime — real-time operating system for Intel architecture & libraries deployed in customer applications
  • INtime SDK — development tools and APIs

Safe Harbor

TenAsys will not pursue civil or criminal action against researchers who discover and report vulnerabilities in good faith, provided that: the researcher does not access, modify, or exfiltrate customer data; does not disrupt production systems; and coordinates disclosure with TenAsys prior to public publication.

Regulatory Notice: This disclosure channel is provided in compliance with Article 13(6) of EU Regulation 2024/2847 (Cyber Resilience Act). TenAsys reports actively exploited vulnerabilities to relevant EU authorities in accordance with Article 14 obligations.


© TENASYS CORPORATION | | Portland, OR, USA