Servstead, LLC

Vulnerability Management Policy

How Servstead identifies, prioritizes, and remediates security vulnerabilities in application code, dependencies, and infrastructure.

Version
1.0
Effective date
July 3, 2026
Policy owner
Servstead, LLC — Information Security Lead
Review cadence
At least annually

Document owner: Servstead, LLC. Version 1.0. Effective date: July 3, 2026.

1. Purpose

This policy defines vulnerability management practices for the Servstead application and its production infrastructure.

2. Scope

Application source code and dependencies (npm packages, framework releases).

Managed cloud infrastructure (Vercel application hosting, Supabase database and storage).

Third-party integrations processing customer or financial data.

3. Dependency monitoring

We monitor application dependencies for published security advisories.

Critical and high-severity vulnerabilities in production dependencies are prioritized for remediation.

Dependency updates are tested in a non-production environment before deployment when feasible.

4. Infrastructure patching

Underlying server and database patching is performed by our managed cloud providers (Vercel, Supabase).

We subscribe to provider security advisories and apply configuration changes as recommended.

5. External reports

Security researchers and customers may report vulnerabilities to servstead@gmail.com.

Good-faith reports are acknowledged within three (3) business days. Confirmed issues are tracked to resolution.

6. Employee endpoints

Personnel with production access must keep operating systems and browsers on supported versions with automatic security updates enabled.

Formal automated endpoint vulnerability scanning will be implemented as team size grows.

7. Remediation timelines

Critical (active exploitation or exposed secrets): remediate within seventy-two (72) hours.

High: remediate within fourteen (14) days.

Medium and low: remediate in the next regular release cycle or within ninety (90) days.

8. Related documents

Information Security Policy: https://servstead.com/policies/security

9. Contact

Vulnerability reports: servstead@gmail.com