English

Places to contact

CERT/CC VINCE (Vulnerability Information and Coordination Environment)

Type
Public reporting channel
Place
International — US-based, globally used
Last checked
2026-09-22
Next check due
2027-03-21

Ways to reach them

  • Submission page · Responsible disclosure programme
    Open contact route · 2026-09-22

    Who may use it: public

    Evidence that this route accepts contact · 2026-09-22

    Vulnerability reports from anyone — you can report with or without a VINCE account. CERT/CC coordinates multi-vendor disclosure where a flaw affects several parties, which is precisely the case for transferable AI jailbreaks and shared model weaknesses.

    'Report a Vulnerability' form at kb.cert.org/vince/, or email cert@cert.org (phone +1 412-268-5800). FLARE-AI routes reports here as one of its named recipients.

  • Homepage · Homepage
    Verification expired

    Evidence that this route accepts contact

What it does

Vulnerability reports from anyone — you can report with or without a VINCE account. CERT/CC coordinates multi-vendor disclosure where a flaw affects several parties, which is precisely the case for transferable AI jailbreaks and shared model weaknesses.

Honest assessment

The strongest escalation path when a vendor ignores you. CERT/CC's leverage is that it will publish on a clock whether or not the vendor cooperates, and vendors know it. Decades of track record in software; its applicability to AI model behaviour is new and being established via FLARE-AI.

How to file

'Report a Vulnerability' form at kb.cert.org/vince/, or email cert@cert.org (phone +1 412-268-5800). FLARE-AI routes reports here as one of its named recipients.

Format

Technical report: affected system and version, description, reproduction steps, impact, and any proof of concept.

Timing

Rolling. CERT/CC operates a published coordinated disclosure policy with a default disclosure timeline (historically 45 days) after which it may publish regardless of vendor response.

What happens after

CERT/CC validates, contacts affected vendors, coordinates a fix and a disclosure date, and may publish a Vulnerability Note in its public database.

What it accepts

Vulnerability reports from anyone — you can report with or without a VINCE account. CERT/CC coordinates multi-vendor disclosure where a flaw affects several parties, which is precisely the case for transferable AI jailbreaks and shared model weaknesses.

What it does not accept

Pure content/quality complaints with no security dimension. Historically security-focused, though the FLARE-AI partnership extends it to AI flaws.

Operated by

CERT Coordination Center, Software Engineering Institute, Carnegie Mellon University

Sources

Something wrong here?