Vulnerability Management Policy
Effective date: April 11, 2026 · Owner: Head of Security · Reviewed at least annually.
Purpose
This policy defines how Himaya identifies, evaluates, prioritizes, and remediates security vulnerabilities across its platform, infrastructure, and supporting systems, so that weaknesses are fixed before they can be exploited.
Scope
It applies to our production application, agent services, APIs and background workers, cloud infrastructure and datastores, internal tooling, and all third-party and open-source dependencies, and to everyone who operates or supports these systems.
How we identify vulnerabilities
We use overlapping sources: continuous dependency and container scanning in CI/CD, infrastructure and configuration scanning against hardened baselines, internal security reviews, periodic third-party penetration testing, and external reports via our responsible-disclosure program.
Severity ratings
Findings are rated using CVSS as a baseline, adjusted for real-world exploitability and exposure of customer data: Critical (exploitable path to customer data or tenant-isolation bypass), High (privilege escalation or sensitive-data exposure), Medium (limited or conditional impact), and Low (minor, defense-in-depth).
Remediation SLAs
Target time to remediate or apply an approved mitigation from confirmation: Critical 24 to 72 hours, High 7 days, Medium 30 days, Low 90 days or the next planned release. If an SLA cannot be met, a documented risk acceptance with a compensating control is approved by the Head of Security.
Triage and workflow
Every finding moves through intake, validation, prioritization, remediation by the owning team, verification by Security, and closure. Recurring patterns feed back into our engineering standards.
Responsible disclosure
We welcome reports from external researchers at hello@himaya.ai. We acknowledge reports, investigate in good faith, and do not pursue action against researchers acting in good faith who avoid privacy violations, data destruction, or service disruption.
Review
This policy is reviewed at least annually and updated as the platform, threat landscape, and regulatory requirements evolve.
