Vulnerability Management and Security Updates Policy
How vulnerabilities are identified, classified, prioritized, remediated, communicated and recorded.
- Version
- 1.0
- Published on
- July 1, 2026
- Last updated
- July 1, 2026
- Next scheduled review
- July 1, 2027
1. Purpose
This Policy defines how vulnerabilities shall be identified, classified, prioritized, fixed and monitored.
2. Sources
Vulnerabilities may be identified through internal testing, dependency alerts, supplier reports, audits, log analysis, customers, researchers, incidents and monitoring.
3. Classification
Vulnerabilities may be classified as critical, high, medium, low or informational, according to impact, exposure and exploitability.
4. Prioritization
Prioritization shall consider risk to data, active exploitation, impact on customers, ease of exploitation, public exposure, financial impact and the existence of a fix.
5. Remediation
Remediation may involve updating dependencies, code changes, configuration adjustment, token revocation, access blocking, temporary mitigation or a definitive fix.
6. Communication
When there is relevant risk, HABORA may notify affected customers, data subjects or authorities, according to legal requirements and risk assessment.
7. Record
Relevant vulnerabilities must generate a record with date, severity, description, affected system, responsible party, status, action taken and fix date.
Contact
Questions, legal requests, privacy requests, formal communications and requests related to this policy should be sent to juridico@haborahub.com.br.
Updates
This policy may be revised to reflect legal, regulatory, technical, commercial or operational changes. The current version will remain available in the HABORA Compliance area. Material changes may require new acceptance by users, where applicable.