Document owner: Servstead, LLC. Version 1.0. Effective date: July 3, 2026.
1. Purpose
This policy defines vulnerability management practices for the Servstead application and its production infrastructure.
2. Scope
Application source code and dependencies (npm packages, framework releases).
Managed cloud infrastructure (Vercel application hosting, Supabase database and storage).
Third-party integrations processing customer or financial data.
3. Dependency monitoring
We monitor application dependencies for published security advisories.
Critical and high-severity vulnerabilities in production dependencies are prioritized for remediation.
Dependency updates are tested in a non-production environment before deployment when feasible.
4. Infrastructure patching
Underlying server and database patching is performed by our managed cloud providers (Vercel, Supabase).
We subscribe to provider security advisories and apply configuration changes as recommended.
5. External reports
Security researchers and customers may report vulnerabilities to servstead@gmail.com.
Good-faith reports are acknowledged within three (3) business days. Confirmed issues are tracked to resolution.
6. Employee endpoints
Personnel with production access must keep operating systems and browsers on supported versions with automatic security updates enabled.
Formal automated endpoint vulnerability scanning will be implemented as team size grows.
7. Remediation timelines
Critical (active exploitation or exposed secrets): remediate within seventy-two (72) hours.
High: remediate within fourteen (14) days.
Medium and low: remediate in the next regular release cycle or within ninety (90) days.
8. Related documents
Information Security Policy: https://servstead.com/policies/security
9. Contact
Vulnerability reports: servstead@gmail.com