Skip to content

Reporting abuse

Resilic hosts a public, per-tenant advisory endpoint for each tenant that opts in — a csaf.<domain> host serving CSAF security advisories so the world can poll them. Because that surface is public, we may be asked — by a third party or a regulator — to act on a tenant serving something they should not. This page explains what we act on and how to report it.

These are operational commitments about a service we run, not legal advice. The public CSAF endpoint is an interoperability and readiness surface; it is not required by the Cyber Resilience Act.

A URL on a csaf.* host that we serve that is:

  • impersonation — a namespace or content spoofing another party;
  • malware or non-advisory payloads abusing the host;
  • clearly illegal content; or
  • content that otherwise misuses the advisory-hosting surface.

We act on the hosting surface we control. Reports about a product or a company that we do not host are out of scope here — contact that party directly.

Email [email protected]. The same address is reachable through the security.txt contact chain on any Resilic-hosted endpoint, and a support ticket tagged csaf-abuse reaches the same queue.

Please include:

  • the URL on the csaf.* host that is the problem,
  • what is wrong, and
  • who is harmed, if applicable.

A single Trust & Safety owner monitors the queue and owns each case end to end. Our triage targets:

Step Target
Acknowledge your report within 1 business day
Initial assessment — in scope? how severe? within 2 business days
Take action, or record a decision to decline within 5 business days
Emergency — active malware or illegal content same day, out of band

We use the least disruptive step that resolves the problem, and escalate only if needed. Every step below the last is reversible once the tenant remediates:

  1. Contact the tenant — notify them, request a correction, and give a fix window (unless it is an emergency).
  2. Stop asserting the namespace — mark the hosting domain stale so we stop publishing under it while the case is investigated.
  3. Deprovision the host — remove the endpoint from our edge so the content is no longer reachable through us.
  4. Suspend the account — for repeat or severe abuse, block the tenant’s access and publishing until the matter is resolved.

Every action is logged with who acted, what they did, when, and why. A declined report is recorded with the reason. There are no silent takedowns.