Post-market & PSIRT cases

When a new advisory lands on a product you already shipped.

The hardest questions come after release: which of our shipped versions are exposed, who looked, what did we decide, and what did we tell customers? The case workflow answers them from the release records you already keep, and writes down every step your team takes.

Limited preview · experimental Offline · every decision made by a named person

Straight status, up front: this is a limited, experimental preview. You can run it in v0.5.0, and its records and commands may still change. It is the surface we most want design partners to shape toward production.

Illustrative brand image, synthetic: a linen-bound journal with divider tabs and a ruled index card clipped to its cover
One journal per case; every entry keeps its author — illustrative brand image · synthetic

The case, from intake to closure

Five steps, each one on the record.

A case keeps a tamper-evident journal. Every step that matters names the person who took it.

01

Open the case

Open a case and bring in the advisory with a note of where it came from. The same advisory arriving under a CVE and a GHSA name is recognised as one, so it is never worked twice.

02

Find what may be exposed

Check the advisory against every shipped release in your local evidence store. Each match is a candidate, never an “affected” verdict, and it says what the match did not settle. The case also lists every release it could not examine, and why, so zero candidates never looks like a clean bill of health.

Candidates can be split by product variant and channel, and weighed against the fielded population you record. Where that inventory is incomplete, the case says partial or unknown, never zero.

03

Triage and decide

A named person owns the case and records the outcome for each candidate. “Not affected” needs a valid justification or it is downgraded, loudly. While candidates are unreviewed or questions are open, the case stays where it is.

04

Fix, verify, or accept the risk

Verify a fix against the release that carries it. An unverified removal blocks closure unless a named person records why. A risk acceptance is time-boxed, surfaced before it expires and never extended automatically.

05

Communicate and disclose

Draft and approve the messages your team sends, and record them once they are sent through your own channels. Export an advisory as a CSAF document watermarked UNSIGNED DRAFT. The disclosure record shows each stage as recorded or not recorded, and “not recorded” never means “not required”.

Where related products may share the problem, the case can propose them for review. A proposal changes no decision.

What the case workflow never does:

  • It never files, publishes, transmits or sends anything. Every message and advisory leaves through your channels, under your authority.
  • It never concludes that you have a legal reporting obligation, and it computes no deadline for you. Those are your determinations.
  • It never states that a product is safe. The record shows what your team knew and did, not a verdict on the product.

For a single release, a newer advisory snapshot can also be checked without opening a case — see vulnerability review. If you work under the EU Cyber Resilience Act, its optional regime view adds reporting drafts, always unsigned.

Replay your last advisory scramble with us.

Pick an advisory your team handled after a release shipped. As a design partner you run the case workflow on your own records, in your own environment, and tell us where it fits and where it does not.