CERT/CC VINCE (Vulnerability Information and Coordination Environment)
- Type
- Public reporting channel
- Lieu
- International — US-based, globally used
- Dernière vérification
- 2026-09-22
- Prochaine vérification
- 2027-03-21
Pas encore traduit — affiché en anglais.
Comment les joindre
- Submission page
- Homepage
Ce qu'il fait
Vulnerability reports from anyone — you can report with or without a VINCE account. CERT/CC coordinates multi-vendor disclosure where a flaw affects several parties, which is precisely the case for transferable AI jailbreaks and shared model weaknesses.
Évaluation franche
The strongest escalation path when a vendor ignores you. CERT/CC's leverage is that it will publish on a clock whether or not the vendor cooperates, and vendors know it. Decades of track record in software; its applicability to AI model behaviour is new and being established via FLARE-AI.
Comment déposer
'Report a Vulnerability' form at kb.cert.org/vince/, or email cert@cert.org (phone +1 412-268-5800). FLARE-AI routes reports here as one of its named recipients.
Format
Technical report: affected system and version, description, reproduction steps, impact, and any proof of concept.
Calendrier
Rolling. CERT/CC operates a published coordinated disclosure policy with a default disclosure timeline (historically 45 days) after which it may publish regardless of vendor response.
Ce qui se passe ensuite
CERT/CC validates, contacts affected vendors, coordinates a fix and a disclosure date, and may publish a Vulnerability Note in its public database.
Ce qu'il accepte
Vulnerability reports from anyone — you can report with or without a VINCE account. CERT/CC coordinates multi-vendor disclosure where a flaw affects several parties, which is precisely the case for transferable AI jailbreaks and shared model weaknesses.
Ce qu'il n'accepte pas
Pure content/quality complaints with no security dimension. Historically security-focused, though the FLARE-AI partnership extends it to AI flaws.
Géré par
CERT Coordination Center, Software Engineering Institute, Carnegie Mellon University