Coordinated Vulnerability Disclosure (CVD) Policy

Coordinated Vulnerability Disclosure (CVD) Policy

1. Introduction & Safe Harbor

Security is a core priority at Pendulum Instruments. We welcome the cybersecurity community’s efforts to help us improve our products. If you conduct vulnerability research in good faith and in accordance with this policy, we consider your actions authorized. We will not initiate or recommend legal action against you, nor will we seek to penalize you for your findings.

2. Scope

This policy applies to all products with digital elements developed and maintained by Pendulum Instruments, including but not limited to:
  • Frequency Counters and Analzyers.
  • Frequency and Time References
  • EMC scanners
  • Desktop applications

Out of Scope: Volumetric attacks (DDoS), social engineering (phishing) against our employees, or physical security attacks against our facilities.

3. How to Report

Please report potential vulnerabilities to our product security team via:

Email: [email protected]

or Web-from on this page.

Please include the product version, environment details, and a proof-of-concept (PoC) or steps to reproduce the issue.

4. Our Commitments and Timelines

We adhere to the following coordinated disclosure timeline:

AcknowledgementWithin 48 hoursA human analyst will confirm receipt of your report and provide a secure tracking identifier.

Triage and AssessmentWithin 7 daysWe will validate the vulnerability, assess its severity, and determine if it meets the criteria for active exploitation.

RemediationWithin 90 daysWe will develop and release a corrective measure (patch or firmware update) to mitigate the vulnerability.

Coordinated DisclosurePost-PatchOnce users have had time to apply the update, we will publicly disclose the vulnerability and appropriately credit the researcher.

 

 

Send Security Report
© Pendulum Instruments 2026 Website Policy