CERT/CC VINCE (Vulnerability Information and Coordination Environment)
- Type
- Public reporting channel
- Place
- International — US-based, globally used
- Last checked
- 2026-09-22
- Next check due
- 2027-03-21
Ways to reach them
- Submission page
- Homepage
What it does
Vulnerability reports from anyone — you can report with or without a VINCE account. CERT/CC coordinates multi-vendor disclosure where a flaw affects several parties, which is precisely the case for transferable AI jailbreaks and shared model weaknesses.
Honest assessment
The strongest escalation path when a vendor ignores you. CERT/CC's leverage is that it will publish on a clock whether or not the vendor cooperates, and vendors know it. Decades of track record in software; its applicability to AI model behaviour is new and being established via FLARE-AI.
How to file
'Report a Vulnerability' form at kb.cert.org/vince/, or email cert@cert.org (phone +1 412-268-5800). FLARE-AI routes reports here as one of its named recipients.
Format
Technical report: affected system and version, description, reproduction steps, impact, and any proof of concept.
Timing
Rolling. CERT/CC operates a published coordinated disclosure policy with a default disclosure timeline (historically 45 days) after which it may publish regardless of vendor response.
What happens after
CERT/CC validates, contacts affected vendors, coordinates a fix and a disclosure date, and may publish a Vulnerability Note in its public database.
What it accepts
Vulnerability reports from anyone — you can report with or without a VINCE account. CERT/CC coordinates multi-vendor disclosure where a flaw affects several parties, which is precisely the case for transferable AI jailbreaks and shared model weaknesses.
What it does not accept
Pure content/quality complaints with no security dimension. Historically security-focused, though the FLARE-AI partnership extends it to AI flaws.
Operated by
CERT Coordination Center, Software Engineering Institute, Carnegie Mellon University